Executive brief
WeenyGenius is a computer lab management system used to control and monitor student computer stations in educational environments. CVE-2026-89177 allows attackers on the same network to intercept unencrypted traffic and capture sensitive data transmitted between teacher and student computers, or inject forged commands to disrupt classroom operations and compromise system integrity.
Technical details
The vulnerability is a use of insecure protocol (CWE-319) stemming from WeenyGenius's reliance on ZMTP Null mode, which provides no encryption or authentication. Unauthenticated attackers on the same network segment can perform passive packet capture to leak transmitted data or active replay attacks to inject forged commands. The attack requires network adjacency but no authentication, user interaction, or special privileges. An attacker can disrupt classroom operations by replaying or forging control messages. The vulnerability affects version 12.2.031 and earlier; patched versions 12.3.033 and later are available.
Affected products
- Howyar WeenyGenius 12.2.031 and earlier
Timeline
- 2026-09-11: disclosed