Description
WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker.
Published: 2026-09-11
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated network impersonation and forced connections to an attacker
Action: Immediate Patch
AI Analysis

Impact

WeenyGenius, a computer lab management system, has an origin validation error that lets an attacker on the same local network spoof the teacher workstation. By sending broadcast packets, the attacker can make student computers attempt to connect to the attacker’s machine, potentially allowing the attacker to receive those connections and launch further malicious activity.

Affected Systems

The vulnerability affects howyar technologies’ WeenyGenius system for any deployed instance that has not applied the vendor’s security update. The vendor recommends upgrading to version 12.3.033 or later to remediate the flaw.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker does not need authentication and only needs to be on the same network segment. Because the exploit is straightforward—sending a simple broadcast packet—the risk is significant in environments where student computers share the LAN with untrusted devices. The attacker could redirect traffic from student machines to an attacker‑controlled host, providing a footholds for further network compromise.

Generated by OpenCVE AI on September 11, 2026 at 09:51 UTC.

Remediation

Vendor Solution

Update to version 12.3.033 or later.


OpenCVE Recommended Actions

  • Update Howyar Technologies’ WeenyGenius to version 12.3.033 or later, which fixes the origin validation error (CWE‑940).
  • If a patch cannot be applied immediately, isolate student computers from other network devices by segmenting the lab LAN or applying ACLs that block broadcast traffic from unknown hosts. This limits an attacker’s ability to send spoofed packets to student machines.
  • Deploy network monitoring or intrusion detection that unauthorized hosts. Such alerts help administrators detect and respond to spoofing attempts before student computers initiate connections.

Generated by OpenCVE AI on September 11, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker.
Title Howyar|WeenyGenius - Origin Validation Error
Weaknesses CWE-940
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-11T07:36:25.977Z

Reserved: 2026-09-11T06:14:51.177Z

Link: CVE-2026-89178

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T08:16:48.947

Modified: 2026-09-11T08:16:48.947

Link: CVE-2026-89178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:00:09Z

Weaknesses
  • CWE-940

    Improper Verification of Source of a Communication Channel