CVE-2024-38287: Rhubcom Turbomeeting
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value.
Affected products
- Rhubcom Turbomeeting: before 8.0 (fixed in 8.0)
Published 2024-07-25. Last modified 2026-06-17.