CVE-2026-89178

8.8

Howyar · WeenyGenius

WeenyGenius contains an origin validation error that allows unauthenticated attackers on the same network to spoof teacher workstations via broadcast packets.

Executive summary

An unauthenticated origin validation vulnerability in Howyar WeenyGenius allows adjacent attackers to intercept student workstation connections, posing a high risk of unauthorized system access.

Vulnerability

This vulnerability is an improper verification of the source of a communication channel (CWE-940). Unauthenticated attackers on the local network can spoof the teacher workstation and broadcast packets to force student computers to connect to an attacker controlled endpoint.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting a high severity due to its potential for full unauthorized control over student-to-teacher communication channels. Successful exploitation could lead to the interception of sensitive academic data, unauthorized remote access to student workstations, or the disruption of classroom management systems, resulting in significant operational downtime.

Remediation

Immediate Action: Update Howyar WeenyGenius to version 12.3.033 or later to remediate the origin validation error.

Proactive Monitoring: Monitor network traffic for anomalous broadcast packets originating from unauthorized devices or unexpected workstation connection requests.

Compensating Controls: Segment the laboratory management network from general traffic to limit the scope of potential adjacent attackers who could send spoofed broadcast packets.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for network-wide impact in educational environments, organizations using WeenyGenius must prioritize this update. Administrators should verify their current version immediately and apply the patch to version 12.3.033 to mitigate the risk of workstation spoofing and unauthorized connection attempts.

More Howyar CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources