CVE-2024-38288: Rhubcom Turbomeeting

High severity, CVSS 7.2. EPSS: 3.2% chance of exploitation in the next 30 days.

A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.

Affected products

  • Rhubcom Turbomeeting: before 8.0 (fixed in 8.0)

Published 2024-07-25. Last modified 2026-06-17.