---
id: CVE-2026-89177
title: >-
  WeenyGenius, a computer lab management system by Howyar Technologies, has a
  Use of Insecure Protocol vulnerability
summary: >-
  WeenyGenius, a computer lab management system by Howyar Technologies, has a
  Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode,
  unauthenticated attackers on the same network can capture packets to leak
  transmit…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-757
vendor: Howyar
product: WeenyGenius
affected:
  - WeenyGenius <= 12.2.031
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T16:17:50.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89177'
references:
  - url: 'https://www.twcert.org.tw/en/cp-139-11200-ffc3c-2.html'
    label: twcert@cert.org.tw
  - url: 'https://www.twcert.org.tw/tw/cp-132-11201-658c0-1.html'
    label: twcert@cert.org.tw
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T15:33:26.050961Z'
epss: 0.00356
epssPercentile: 0.26634
ingestedAt: '2026-09-11T16:45:47.860Z'
---

## Overview

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
