RustDesk
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 18 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 6, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →RustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection
RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
RustDesk hbbs/hbbr Servers Broker Connections Without Any Authorization Check
RustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL Policies
RustDesk Server Controls All Handshake Entropy (Salt/Challenge), Enabling Offline Brute-Force
RustDesk Auth Proof Uses Server-Controlled Salt/Challenge and Fast Double-SHA256, Enabling Offline Brute-Force
RustDesk Client Accepts Unauthenticated stop-service Command via Strategy Payload
RustDesk rustdesk://config/ URI Silently Re-homes Client to Attacker-Controlled Server
RustDesk Client Transmits Preset Address Book Password Verbatim in Heartbeat Sync
RustDesk HTTP Client Silently Accepts Invalid TLS Certificates After Handshake Failure
Monitor RustDesk in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.