RustDesk Client Improper Certificate Validation Vulnerability Allowing Adversary-in-the-Middle Attacks

Vulnerability

A vulnerability in the RustDesk Client's HTTP API that affects multiple platforms, including Windows, MacOS, Linux, iOS, and Android, has been identified. This vulnerability arises from improper certificate validation in the TLS transport modules, allowing for Adversary-in-the-Middle (AiTM) attacks. The issue is linked to the HTTP client in the source file 'hbbs_http/http_client.rs', where the TLS retry routine is set to accept invalid certificates. This vulnerability impacts RustDesk Client versions through 1.4.5.

Impact

Exploitation of this vulnerability could lead to Adversary-in-the-Middle attacks, where an attacker could intercept and potentially alter communications between the client and server.

Added: Mar 5, 2026, 4:25 PM
Updated: Mar 5, 2026, 4:25 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
5.0
exploitability
6.4
remediation
0.0
relevance
3.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.