Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rustdesk

First CVE: Feb 6, 2024Active for: 2 yearsTotal CVEs: 14
45.5
VTI Score
High

RustDesk is an open-source remote-access software platform whose vulnerability profile centers on its core client and server products and skews strongly toward critical-severity outcomes. The recurring weaknesses—weak password hashing, cleartext credential transmission, improper certificate validation, and authorization gaps—reflect the authentication and transport-security demands inherent to a remote-desktop platform that must protect administrative access and sensitive data in motion. Defenders should prioritize patching this vendor's releases and validate secure configuration of trust anchors and credential handling; current exploitation and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
3.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rustdesk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 2024
2 years ago
Most Recent CVE
Jul 10, 2026
14 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-57850HIGH
RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera,
Jul 10, 20268.336NONO
CVE-2026-58056HIGH
RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A
Jun 28, 20267.635NONO
CVE-2026-30793CRITICAL
Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge mo
Mar 5, 20269.829NONO
CVE-2026-30789CRITICAL
Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-cli
Mar 5, 20269.829NONO
CVE-2026-30783CRITICAL
A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) al
Mar 5, 20269.827NONO
CVE-2024-25140CRITICAL
A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5
Feb 6, 20249.827NONO
CVE-2026-30796HIGH
Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS
Mar 5, 20267.526NONO
CVE-2026-30792HIGH
A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules)
Mar 5, 20268.126NONO
CVE-2026-30798HIGH
Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linu
Mar 5, 20267.524NONO
CVE-2026-30797HIGH
Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) al
Mar 5, 20268.124NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
64%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.1%)
Network13 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (85.7%)
High2 (14.3%)
Unknown0 (0.0%)
User Interaction
None14 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (21.4%)
High0 (0.0%)
None11 (78.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rustdesk.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rustdesk — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rustdesk's Products

View all 3 CNAs →

Top CWEs