Description
WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.
Published: 2026-09-11
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated local network attackers can capture or replay traffic, leaking data or disrupting classroom operations
Action: Immediate Patch
AI Analysis

Impact

WeenyGenius relies on ZMTP Null mode, an insecure protocol that does not provide encryption or integrity protection. Because of this, anyone on the same network can intercept packets to expose information or replay forged commands, potentially causing disruptions to lesson plans and data leakage.

Affected Systems

The vulnerability affects all Howyar WeenyGenius installations before version 12.3.033. The vendor recommends updating to version 12.3.033 or later to remove the insecure protocol support.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity flaw. The EPSS score is not available, but the flaw allows unauthenticated, local network attackers to exploit the system. It is not listed in CISA KEV, yet the lack of authentication combined with local network access makes exploitation likely if an attacker gains proximity.

Generated by OpenCVE AI on September 11, 2026 at 08:21 UTC.

Remediation

Vendor Solution

Update to version 12.3.033 or later.


OpenCVE Recommended Actions

  • Upgrade WeenyGenius to version 12.3.033 or later to eliminate the insecure ZMTP Null mode.
  • If an immediate upgrade is not possible, block ZMTP Null mode traffic using firewall or ACL rules to prevent packet sniffing and replay attacks.
  • Segment the lab network and restrict access to the WeenyGenius server to authorized personnel only to limit exposure to unauthenticated local attackers.

Generated by OpenCVE AI on September 11, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.
Title Howyar|WeenyGenius - Use of Insecure Protocol
Weaknesses CWE-757
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-11T07:35:40.861Z

Reserved: 2026-09-11T06:14:49.953Z

Link: CVE-2026-89177

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T08:16:48.813

Modified: 2026-09-11T08:16:48.813

Link: CVE-2026-89177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:30:11Z

Weaknesses
  • CWE-757

    Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')