Ad

CVE-2026-30796

HIGH CVSS 4.0: 8.7 EPSS 0.02%
Updated Mar 25, 2026
Apple
Parameter Value
CVSS 8.7 (HIGH)
Affected Versions before 1.7.5
Type CWE-319 (Cleartext Transmission)
Vendor Apple
Public PoC No

Cleartext Transmission of Sensitive Information vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Address book sync API modules) allows Sniffing Attacks. This vulnerability is associated with program files Closed source — API endpoint handling heartbeat sync and program routines Heartbeat API handler (accepts preset-address-book-password in plaintext). This issue affects RustDesk Server Pro: through 1.7.5.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products 4

Configuration From (including) Up to (excluding)
Rustdesk Rustdesk_Server
cpe:2.3:a:rustdesk:rustdesk_server:*:*:*:*:pro:*:*:*
<= 1.7.5
Apple Macos
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Microsoft Windows
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*