ZeroHour

CVE-2026-89178

niche

Origin Validation Error in Howyar WeenyGenius Computer Lab Management

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

WeenyGenius, a computer lab management system from Howyar Technologies, fails to properly validate the origin of broadcast packets, allowing an unauthenticated attacker on the same network to impersonate the teacher workstation. The attacker sends forged broadcast packets on the local network, which causes student client computers to initiate connections back to the attacker's machine. By impersonating the teacher workstation, the attacker can establish sessions with student computers and interact with or influence them, with CVSS 4.0 scoring high potential impact to confidentiality, integrity, and availability of the student clients. Organizations running WeenyGenius — typically schools and institutions with managed computer labs — are affected. There is no evidence of exploitation in the wild, no CISA KEV listing, and no public proof-of-concept at this time.

What to do: Check with Howyar Technologies and TWCERT/CC advisories for a patched release, since specific fixed version numbers were not provided in the available data. Until a patch is applied, mitigate by segmenting or restricting broadcast traffic on lab VLANs and limiting which hosts can send broadcast packets toward student clients, and monitor the lab network for unauthenticated hosts answering as the teacher workstation.

Affected
Howyar Technologies WeenyGenius (computer lab management system)
Estimated exposure
nicheunknown; plausibly in the low thousands of installations (school/institutional computer labs running this niche vendor product) — No public install counts or scan data exist for WeenyGenius; it is a niche lab-management tool deployed primarily in educational computer labs, so exposure is limited to local networks where its teacher and student clients are installed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker.

Weakness
CWE-940
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.