Executive brief
WeenyGenius is a computer lab management system used to manage student and teacher computers in educational environments. An unauthenticated attacker on the same network can intercept and replay student connection packets to forge the appearance that a student remains connected, disrupting classroom operations and potentially masking unauthorized access to lab systems.
Technical details
CVE-2026-89179 is a missing integrity check vulnerability in WeenyGenius's ZMTP-based communication protocol. The vulnerability allows unauthenticated attackers on the same network to intercept a student's connection packet and replay it to the system, forging the appearance that the student remains connected even after they have disconnected. The attack requires network adjacency but no authentication or user interaction. The vulnerable component lacks cryptographic integrity verification for connection state messages. This vulnerability has been patched in version 12.3.033 and later.
Affected products
- Howyar WeenyGenius 12.2.031 and earlier
Timeline
- 2026-09-11: disclosed