CVE-2026-89177
8.7
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Howyar | WeenyGenius | 0 <= 12.2.031 | affected |
Weaknesses
- CWE-757: CWE-757 / CWE-319 / CWE-353
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://www.twcert.org.tw/tw/cp-132-11201-658c0-1.html
- https://www.twcert.org.tw/en/cp-139-11200-ffc3c-2.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.