Skip to content
Noroxi

rustdesk records

12 published records for vendor rustdesk.

All records

12 records
  • A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhan

    CriticalCVSS 9.8No exploitEPSS 1%

    rustdesk · rustdeskFeb 6, 2024

  • RustDesk rustdesk://config/ URI Silently Re-homes Client to Attacker-Controlled Server

    CriticalCVSS 9.3No exploitEPSS 1%

    rustdesk · rustdeskMar 5, 2026

  • RustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation

    CriticalCVSS 9.3No exploitEPSS 0%

    rustdesk · rustdeskMar 5, 2026

  • RustDesk Client Accepts Pseudo-Encrypted Config Strings Without Cryptographic Validation

    HighCVSS 8.7No exploitEPSS 0%

    rustdesk · rustdeskMar 5, 2026

  • CVE-2026-3598
    34Monitor

    RustDesk Server Generates Config Strings Using Reversible Encoding (Base64 + Reverse) Instead of Encryption

    HighCVSS 8.7No exploitEPSS 0%

    rustdesk · rustdesk serverMar 5, 2026

  • RustDesk HTTP Client Silently Accepts Invalid TLS Certificates After Handshake Failure

    HighCVSS 8.7No exploitEPSS 0%

    rustdesk · rustdeskMar 5, 2026

  • RustDesk Client Blindly Merges Unauthenticated Strategy Payloads, Bypassing Local Security Settings

    HighCVSS 8.3No exploitEPSS 0%

    rustdesk · rustdeskMar 5, 2026

  • RustDesk Client Accepts Unauthenticated stop-service Command via Strategy Payload

    HighCVSS 8.2No exploitEPSS 0%

    rustdesk · rustdeskMar 5, 2026

  • RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)

    HighCVSS 8.2No exploitEPSS 0%

    rustdesk · rustdeskMar 5, 2026

  • RustDesk Client Transmits Preset Address Book Password Verbatim in Heartbeat Sync

    MediumCVSS 6.9No exploitEPSS 0%

    rustdesk · rustdesk serverMar 5, 2026

  • RustDesk Auth Proof Uses Server-Controlled Salt/Challenge and Fast Double-SHA256, Enabling Offline Brute-Force

    MediumCVSS 5.7No exploitEPSS 0%

    rustdesk · rustdeskMar 5, 2026

  • RustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL Policies

    MediumCVSS 4.8No exploitEPSS 0%

    rustdesk · rustdeskMar 5, 2026