【Security Vulnerability Alert】Howyar|WeenyGenius - 3 Critical Security Vulnerabilities

 
2026/9/24 ~ 2027/3/24
View Count:39

Forwarded from Taiwan Computer Emergency Response Team / Coordination Center Security Information Alert TWCERTCC-200-202609-00000018

[Content Description]
Howyar's product WeenyGenius contains 4 security vulnerabilities, including 3 critical security vulnerabilities:
【Howyar|WeenyGenius - Missing Authentication】(CVE-2026-89176, CVSS:8.8) Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can disrupt normal classroom operations, whereas impersonating a teacher can control student computers.
【Howyar|WeenyGenius - Use of Insecure Protocol 】(CVE-2026-89177, CVSS:8.8) Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to obtain transmitted data.
【Howyar|WeenyGenius - Origin Validation Error 】(CVE-2026-89178, CVSS:8.8) Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker.
【Howyar|WeenyGenius - Missing Support for Integrity Check 】(CVE-2026-89179, CVSS:4.3) Unauthenticated attackers on the same network can intercept a student's connection packet and replay it, thereby forging the appearance that the student remains connected.

[Affected Platforms]
WeenyGenius versions 12.2.031 (inclusive) and earlier

[Recommended Measures]
Update to version 12.3.033 (inclusive) or later.

[References]
1. https://www.twcert.org.tw/tw/cp-132-11201-658c0-1.html

Files
system_update_alt參考資料
Top↑