Impact
WeenyGenius relies on ZMTP Null mode, an insecure protocol that does not provide encryption or integrity protection. Because of this, anyone on the same network can intercept packets to expose information or replay forged commands, potentially causing disruptions to lesson plans and data leakage.
Affected Systems
The vulnerability affects all Howyar WeenyGenius installations before version 12.3.033. The vendor recommends updating to version 12.3.033 or later to remove the insecure protocol support.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity flaw. The EPSS score is not available, but the flaw allows unauthenticated, local network attackers to exploit the system. It is not listed in CISA KEV, yet the lack of authentication combined with local network access makes exploitation likely if an attacker gains proximity.
OpenCVE Enrichment