CVE-2026-89178
nicheOrigin Validation Error in Howyar WeenyGenius Computer Lab Management
WeenyGenius, a computer lab management system from Howyar Technologies, fails to properly validate the origin of broadcast packets, allowing an unauthenticated attacker on the same network to impersonate the teacher workstation. The attacker sends forged broadcast packets on the local network, which causes student client computers to initiate connections back to the attacker's machine. By impersonating the teacher workstation, the attacker can establish sessions with student computers and interact with or influence them, with CVSS 4.0 scoring high potential impact to confidentiality, integrity, and availability of the student clients. Organizations running WeenyGenius — typically schools and institutions with managed computer labs — are affected. There is no evidence of exploitation in the wild, no CISA KEV listing, and no public proof-of-concept at this time.
What to do: Check with Howyar Technologies and TWCERT/CC advisories for a patched release, since specific fixed version numbers were not provided in the available data. Until a patch is applied, mitigate by segmenting or restricting broadcast traffic on lab VLANs and limiting which hosts can send broadcast packets toward student clients, and monitor the lab network for unauthenticated hosts answering as the teacher workstation.
| Howyar Technologies WeenyGenius (computer lab management system) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker.
- Weakness
- CWE-940
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.