Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 81%

CVE-2026-30789: CWE-916 Use of Password Hash With Insufficient Computational Effort in rustdesk-client RustDesk Client

0
Medium
VulnerabilityCVE-2026-30789cvecve-2026-30789cwe-294cwe-916cwe-307
Published: 03/05/2026 (03/05/2026, 15:41:51 UTC)
Source: CVE Database V5
Vendor/Project: rustdesk-client
Product: RustDesk Client

Description

Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, peer authentication modules) allows Password Brute Forcing. The authentication proof is SHA256(SHA256(password + salt) + challenge), where both the salt and the challenge are generated entirely by the server with no client-side nonce, and the hash uses no slow key-derivation function. A rogue or on-path API/relay server (see CVE-2026-30794 / CVE-2026-30797) can issue a chosen salt and challenge, capture the resulting proof, and recover the password offline. The capture-replay claim (CWE-294) is withdrawn: the challenge is regenerated per connection (challenge = Config::get_auto_password(6)), so a captured proof is not replayable against the legitimate server. The 1.4.7 OTP brute-force limiter and the existing LOGIN_FAILURES counter constrain only ONLINE attempts and do not address offline recovery. This vulnerability is associated with program files src/client.rs and program routines handle_hash(), handle_login_from_ui() (login proof construction). This issue affects RustDesk Client: through 1.4.8.

CVSS v4.0

Score 5.7medium

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected software

crates.iomore threats →ai
rustdesk-client
pkg:cargo/rustdesk-client
Affected versions
=0<=1.4.8

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/22/2026, 14:16:21 UTC

Technical Analysis

CVE-2026-30789 describes a vulnerability in RustDesk Client (up to version 1.4.8) where the password hashing mechanism uses insufficient computational effort, relying on double SHA256 without a slow key derivation function. The authentication proof is constructed as SHA256(SHA256(password + salt) + challenge), with both salt and challenge generated solely by the server. This allows an attacker controlling or intercepting the server API or relay to choose salt and challenge values, capture the resulting proof, and perform offline brute forcing to recover the password. Although the challenge changes per connection preventing replay attacks, the lack of a slow hashing function enables efficient offline attacks. Online brute force protections exist but do not mitigate offline password recovery.

Potential Impact

An attacker who can act as or intercept the server can capture authentication proofs and perform offline brute force attacks to recover user passwords. This compromises user credentials without requiring repeated online authentication attempts. The vulnerability weakens the authentication security of RustDesk Client, potentially allowing unauthorized access if passwords are recovered. However, replay attacks are not feasible due to per-connection challenge regeneration. The overall severity is medium based on CVSS 5.7.

Mitigation Recommendations

No official patch or fix is currently available for this vulnerability. Users should monitor the vendor advisory for updates. Until a fix is released, relying on strong, high-entropy passwords may reduce the risk of offline brute forcing. The existing online brute force protections do not mitigate offline attacks. Avoid using RustDesk Client versions up to 1.4.8 in high-risk environments where password compromise would be critical.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VULSec
Date Reserved
2026-03-05T14:13:37.202Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 69a9c05f460e1c85df0c5c51

Added to database: 03/05/2026, 17:41:51 UTC

Last enriched: 06/22/2026, 14:16:21 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 412

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses