CVE-2026-89179
Received Received - Intake

Missing Integrity Check in WeenyGenius Lab Management System

Vulnerability report for CVE-2026-89179, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: TWCERT/CC

Description

WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability. Unauthenticated attackers on the same network can intercept a student's connection packet and replay it, thereby forging the appearance that the student remains connected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
howyar_technologies weenygenius *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-353 The product uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability. Unauthenticated attackers on the same network can intercept and replay a student's connection packet, making it appear the student remains connected even after they disconnect.

Impact Analysis

An attacker could exploit this to maintain unauthorized access to a student's session, potentially allowing them to perform actions or access resources as if they were the legitimate user. This could lead to data theft, unauthorized system changes, or disruption of lab operations.

Compliance Impact

This vulnerability may violate compliance requirements that mandate session integrity and protection against replay attacks, such as GDPR's data integrity principle or HIPAA's access controls. Organizations using WeenyGenius could face compliance violations and potential penalties.

Mitigation Strategies

Implement network-level encryption and authentication to prevent packet interception and replay attacks. Ensure all connections to WeenyGenius are over secure channels like TLS.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89179. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart