Description

Improper Restriction of Excessive Authentication Attempts, Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Peer authentication, API login modules), rustdesk-server RustDesk Server (OSS) rustdesk-server on Windows, MacOS, Linux (Peer authentication, API login modules) allows Password Brute Forcing. This vulnerability is associated with program files src/server/connection.Rs and program routines Salt/challenge generation, SHA256(SHA256(pwd+salt)+challenge) verification. This issue affects RustDesk Server Pro: through 1.7.5; RustDesk Server (OSS): through 1.1.15.

INFO

Published Date :

2026-03-05T15:49:15.539Z

Last Modified :

2026-03-05T16:59:25.324Z

Source :

VULSec
AFFECTED PRODUCTS

The following products are affected by CVE-2026-30790 vulnerability.

Vendors Products
Rustdesk-server
  • Rustdesk Server
  • Rustdesk Server Pro
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-30790.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability