Impact
The flaw is a Lack of Integrity Check that allows an unauthenticated attacker on the same network to capture a student’s connection packet and replay it, deceiving the system into believing the student is still connected. The result is a false presence record, which may affect attendance monitoring, resource allocation, or audit trails. The vulnerability is specifically code‑checked as CWE‑353 and does not provide the attacker with execution privileges or direct access to data, but it does enable the attacker to manipulate status reporting.
Affected Systems
The software affected is the WeenyGenius computer lab management system developed by Howyar Technologies, available under the product name Howyar:WeenyGenius. No specific version constraints are provided in the advisory, but the vendor’s own solution indicates that versions prior to 12.3.033 contain the weakness and that upgrading to 12.3.033 or later resolves it.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate overall severity. Because the attack requires packet interception on the same local network, the probability of exploitation is limited to environments where a malicious actor can observe network traffic; the EPSS score is not available, so no precise exploitation likelihood can be provided. The vulnerability is not currently listed in CISA’s KEV catalog, suggesting no publicly known exploit. The likely attack path involves an attacker positioned on the same LAN sniffing the WeenyGenius traffic, capturing a legitimate login packet and replaying it to the system. No privileged access or software execution is required.
OpenCVE Enrichment