Junglewise Threat Intelligence

CVE-2026-89177: Howyar WeenyGenius insecure protocol vulnerability in ZMTP

CVE-2026-89177 · Severity: high · CVSS 8.8 · Published 2026-09-11

Technologies: Howyar WeenyGenius. Vendors: Howyar.

Executive brief

WeenyGenius is a computer lab management system used to control and monitor student computer stations in educational environments. CVE-2026-89177 allows attackers on the same network to intercept unencrypted traffic and capture sensitive data transmitted between teacher and student computers, or inject forged commands to disrupt classroom operations and compromise system integrity.

Technical details

The vulnerability is a use of insecure protocol (CWE-319) stemming from WeenyGenius's reliance on ZMTP Null mode, which provides no encryption or authentication. Unauthenticated attackers on the same network segment can perform passive packet capture to leak transmitted data or active replay attacks to inject forged commands. The attack requires network adjacency but no authentication, user interaction, or special privileges. An attacker can disrupt classroom operations by replaying or forging control messages. The vulnerability affects version 12.2.031 and earlier; patched versions 12.3.033 and later are available.

Affected products

  • Howyar WeenyGenius 12.2.031 and earlier

Timeline

  • 2026-09-11: disclosed

References

Related threats