ZeroHour

CVE-2026-89177

Insecure ZMTP Null-mode protocol in Howyar WeenyGenius lab management system

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

WeenyGenius, a computer lab management system from Howyar Technologies, communicates using ZMTP in Null mode, which provides no encryption or authentication for traffic exchanged between the instructor console and lab client machines. An unauthenticated attacker on the same network can passively capture packets to leak whatever data the system transmits, or actively replay and forge commands to disrupt classroom operations. The attack requires only adjacent network access (no privileges and no user interaction) and can cause high-impact loss of confidentiality, integrity, and availability on the affected lab systems per its CVSS 4.0 score of 8.7. Any organization running WeenyGenius, typically schools or training centers with managed computer labs, is affected; the available data does not specify vulnerable version ranges. There are currently no reports of in-the-wild exploitation, no known public proof-of-concept, and the issue is not listed in CISA's KEV catalog.

What to do: Segment WeenyGenius deployments (e.g., a dedicated lab VLAN) so that only authorized lab machines share the network, since the attack requires adjacent network access. Contact Howyar Technologies for a patched release and upgrade lab machines when one is available, as no fixed version is specified in the available data; in the meantime, monitor lab networks for unexpected or replayed client commands.

Affected
Howyar Technologies WeenyGenius (computer lab management system)
Estimated exposure
unknown (no public adoption figures; deployments are limited to individual school lab networks) — No public install counts, market-share data, or internet-exposed device scans exist for this niche education-sector lab management product, and exploitation requires the attacker to already be on the same LAN as the lab machines, so total…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.

Weakness
CWE-757
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.