CVE-2026-30789: CWE-916 Use of Password Hash With Insufficient Computational Effort in rustdesk-client RustDesk Client
Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, peer authentication modules) allows Password Brute Forcing. The authentication proof is SHA256(SHA256(password + salt) + challenge), where both the salt and the challenge are generated entirely by the server with no client-side nonce, and the hash uses no slow key-derivation function. A rogue or on-path API/relay server (see CVE-2026-30794 / CVE-2026-30797) can issue a chosen salt and challenge, capture the resulting proof, and recover the password offline. The capture-replay claim (CWE-294) is withdrawn: the challenge is regenerated per connection (challenge = Config::get_auto_password(6)), so a captured proof is not replayable against the legitimate server. The 1.4.7 OTP brute-force limiter and the existing LOGIN_FAILURES counter constrain only ONLINE attempts and do not address offline recovery. This vulnerability is associated with program files src/client.rs and program routines handle_hash(), handle_login_from_ui() (login proof construction). This issue affects RustDesk Client: through 1.4.8.
AI Analysis
Technical Summary
CVE-2026-30789 describes a vulnerability in RustDesk Client (up to version 1.4.8) where the password hashing mechanism uses insufficient computational effort, relying on double SHA256 without a slow key derivation function. The authentication proof is constructed as SHA256(SHA256(password + salt) + challenge), with both salt and challenge generated solely by the server. This allows an attacker controlling or intercepting the server API or relay to choose salt and challenge values, capture the resulting proof, and perform offline brute forcing to recover the password. Although the challenge changes per connection preventing replay attacks, the lack of a slow hashing function enables efficient offline attacks. Online brute force protections exist but do not mitigate offline password recovery.
Potential Impact
An attacker who can act as or intercept the server can capture authentication proofs and perform offline brute force attacks to recover user passwords. This compromises user credentials without requiring repeated online authentication attempts. The vulnerability weakens the authentication security of RustDesk Client, potentially allowing unauthorized access if passwords are recovered. However, replay attacks are not feasible due to per-connection challenge regeneration. The overall severity is medium based on CVSS 5.7.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. Users should monitor the vendor advisory for updates. Until a fix is released, relying on strong, high-entropy passwords may reduce the risk of offline brute forcing. The existing online brute force protections do not mitigate offline attacks. Avoid using RustDesk Client versions up to 1.4.8 in high-risk environments where password compromise would be critical.
CVE-2026-30789: CWE-916 Use of Password Hash With Insufficient Computational Effort in rustdesk-client RustDesk Client
Description
Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, peer authentication modules) allows Password Brute Forcing. The authentication proof is SHA256(SHA256(password + salt) + challenge), where both the salt and the challenge are generated entirely by the server with no client-side nonce, and the hash uses no slow key-derivation function. A rogue or on-path API/relay server (see CVE-2026-30794 / CVE-2026-30797) can issue a chosen salt and challenge, capture the resulting proof, and recover the password offline. The capture-replay claim (CWE-294) is withdrawn: the challenge is regenerated per connection (challenge = Config::get_auto_password(6)), so a captured proof is not replayable against the legitimate server. The 1.4.7 OTP brute-force limiter and the existing LOGIN_FAILURES counter constrain only ONLINE attempts and do not address offline recovery. This vulnerability is associated with program files src/client.rs and program routines handle_hash(), handle_login_from_ui() (login proof construction). This issue affects RustDesk Client: through 1.4.8.
CVSS v4.0
Score 5.7medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-30789 describes a vulnerability in RustDesk Client (up to version 1.4.8) where the password hashing mechanism uses insufficient computational effort, relying on double SHA256 without a slow key derivation function. The authentication proof is constructed as SHA256(SHA256(password + salt) + challenge), with both salt and challenge generated solely by the server. This allows an attacker controlling or intercepting the server API or relay to choose salt and challenge values, capture the resulting proof, and perform offline brute forcing to recover the password. Although the challenge changes per connection preventing replay attacks, the lack of a slow hashing function enables efficient offline attacks. Online brute force protections exist but do not mitigate offline password recovery.
Potential Impact
An attacker who can act as or intercept the server can capture authentication proofs and perform offline brute force attacks to recover user passwords. This compromises user credentials without requiring repeated online authentication attempts. The vulnerability weakens the authentication security of RustDesk Client, potentially allowing unauthorized access if passwords are recovered. However, replay attacks are not feasible due to per-connection challenge regeneration. The overall severity is medium based on CVSS 5.7.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. Users should monitor the vendor advisory for updates. Until a fix is released, relying on strong, high-entropy passwords may reduce the risk of offline brute forcing. The existing online brute force protections do not mitigate offline attacks. Avoid using RustDesk Client versions up to 1.4.8 in high-risk environments where password compromise would be critical.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VULSec
- Date Reserved
- 2026-03-05T14:13:37.202Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 69a9c05f460e1c85df0c5c51
Added to database: 03/05/2026, 17:41:51 UTC
Last enriched: 06/22/2026, 14:16:21 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 412
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.