Executive brief
WeenyGenius is a computer lab management system used to control and monitor student computers in educational settings. An unauthenticated attacker on the same network can impersonate the teacher's workstation and send broadcast commands, causing student computers to establish connections with the attacker instead of the legitimate teacher. This allows the attacker to gain remote control over student machines, disrupting classroom operations and potentially accessing sensitive student data.
Technical details
CVE-2026-89178 is an origin validation error in WeenyGenius versions 12.2.031 and earlier. The vulnerability exists because the system does not properly validate the origin/source of broadcast packets used for teacher-to-student communication. Unauthenticated attackers on the same network segment can exploit this by sending spoofed broadcast packets claiming to originate from the teacher workstation, causing student computers to initiate connections with the attacker. No authentication or user interaction is required; the attack is feasible against any student endpoint reachable on the network. An attacker gaining such access can achieve full remote control over affected student computers. The fix is to update to WeenyGenius version 12.3.033 or later.
Affected products
- Howyar WeenyGenius 12.2.031 and earlier
Timeline
- 2026-09-11: disclosed
- 2026-09-11: patched: Fix available in version 12.3.033 or later