CVE-2026-89178
8.7
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Howyar | WeenyGenius | 0 <= 12.2.031 | affected |
Weaknesses
- CWE-940: CWE-940 Improper Verification of Source of a Communication Channel
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://www.twcert.org.tw/tw/cp-132-11201-658c0-1.html
- https://www.twcert.org.tw/en/cp-139-11200-ffc3c-2.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.