Description
WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability. Unauthenticated attackers on the same network can intercept a student's connection packet and replay it, thereby forging the appearance that the student remains connected.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: False presence reporting
Action: Apply Patch
AI Analysis

Impact

The flaw is a Lack of Integrity Check that allows an unauthenticated attacker on the same network to capture a student’s connection packet and replay it, deceiving the system into believing the student is still connected. The result is a false presence record, which may affect attendance monitoring, resource allocation, or audit trails. The vulnerability is specifically code‑checked as CWE‑353 and does not provide the attacker with execution privileges or direct access to data, but it does enable the attacker to manipulate status reporting.

Affected Systems

The software affected is the WeenyGenius computer lab management system developed by Howyar Technologies, available under the product name Howyar:WeenyGenius. No specific version constraints are provided in the advisory, but the vendor’s own solution indicates that versions prior to 12.3.033 contain the weakness and that upgrading to 12.3.033 or later resolves it.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate overall severity. Because the attack requires packet interception on the same local network, the probability of exploitation is limited to environments where a malicious actor can observe network traffic; the EPSS score is not available, so no precise exploitation likelihood can be provided. The vulnerability is not currently listed in CISA’s KEV catalog, suggesting no publicly known exploit. The likely attack path involves an attacker positioned on the same LAN sniffing the WeenyGenius traffic, capturing a legitimate login packet and replaying it to the system. No privileged access or software execution is required.

Generated by OpenCVE AI on September 11, 2026 at 08:21 UTC.

Remediation

Vendor Solution

Update to version 12.3.033 or later.


OpenCVE Recommended Actions

  • Upgrade WeenyGenius to version 12.3.033 or later according to Howyar’s advisory.
  • If an upgrade is not immediately possible, restrict local network access to verified lab users and isolate the WeenyGenius management network from open or untrusted segments.
  • Implement network monitoring or intrusion detection to detect repeated credential or packet replay events and take remedial action when detected.

Generated by OpenCVE AI on September 11, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability. Unauthenticated attackers on the same network can intercept a student's connection packet and replay it, thereby forging the appearance that the student remains connected.
Title Howyar|WeenyGenius - Missing Support for Integrity Check
Weaknesses CWE-353
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-11T15:30:14.795Z

Reserved: 2026-09-11T06:14:52.086Z

Link: CVE-2026-89179

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-11T08:16:49.080

Modified: 2026-09-11T16:17:50.437

Link: CVE-2026-89179

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:30:11Z

Weaknesses
  • CWE-353

    Missing Support for Integrity Check