CVE-2026-89177: Howyar|WeenyGenius - Use of Insecure Protocol
WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeenyGenius (Howyar Technologies)to a version that resolves this vulnerability.Fixed in 12.3.033
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Systems running Howyar WeenyGenius are exposed when an unauthenticated attacker can access the same network. The attacker does not need credentials or user interaction.
What can an attacker do over the affected network?
An attacker can capture transmitted packets and leak their contents. They can also replay forged commands, which can disrupt classroom operations.
How can I tell whether a system is affected?
The affected condition is reliance on ZMTP Null mode in Howyar WeenyGenius. The provided information does not identify affected versions or provide a detection method.