Rhubcom's vulnerability footprint is centered on its TurboMeeting conferencing and collaboration platform, with the durable signal concentrated on web-application input-handling weaknesses including command injection, SQL injection, and weak password-recovery mechanisms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rhubcom over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-38289CRITICAL A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passw | Jul 25, 2024 | 9.8 | 60 | NO | YES |
CVE-2024-38288HIGH A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to e | Jul 25, 2024 | 7.2 | 31 | NO | YES |
CVE-2024-38287CRITICAL The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting | Jul 25, 2024 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rhubcom.
Media articles that mention a CVE ID that affects a product developed by Rhubcom — matched by CVE ID, not by vendor name.