CVE-2026-89178
8.8Howyar · WeenyGenius
WeenyGenius contains an origin validation error that allows unauthenticated attackers on the same network to spoof teacher workstations via broadcast packets.
Executive summary
An unauthenticated origin validation vulnerability in Howyar WeenyGenius allows adjacent attackers to intercept student workstation connections, posing a high risk of unauthorized system access.
Vulnerability
This vulnerability is an improper verification of the source of a communication channel (CWE-940). Unauthenticated attackers on the local network can spoof the teacher workstation and broadcast packets to force student computers to connect to an attacker controlled endpoint.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting a high severity due to its potential for full unauthorized control over student-to-teacher communication channels. Successful exploitation could lead to the interception of sensitive academic data, unauthorized remote access to student workstations, or the disruption of classroom management systems, resulting in significant operational downtime.
Remediation
Immediate Action: Update Howyar WeenyGenius to version 12.3.033 or later to remediate the origin validation error.
Proactive Monitoring: Monitor network traffic for anomalous broadcast packets originating from unauthorized devices or unexpected workstation connection requests.
Compensating Controls: Segment the laboratory management network from general traffic to limit the scope of potential adjacent attackers who could send spoofed broadcast packets.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for network-wide impact in educational environments, organizations using WeenyGenius must prioritize this update. Administrators should verify their current version immediately and apply the patch to version 12.3.033 to mitigate the risk of workstation spoofing and unauthorized connection attempts.
More Howyar CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section