CyberRota Analysis
AI-GeneratedFreeRDP versions prior to 3.30.0 are vulnerable to a server-side authentication bypass during the RDSTLS handshake, allowing unauthenticated remote clients to exploit the flaw by sending a Capabilities PDU instead of the required Authentication Request PDU. This results in the server incorrectly treating the session as authenticated, potentially granting unauthorized access to sensitive resources. Organizations using FreeRDP should prioritize addressing this vulnerability to mitigate the risk of unauthorized access to their systems.
Original NVD Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241.