Forwarded from TWCERT/CC Security Advisory TWCERTCC-200-202609-00000018
The WeenyGenius product by HaoYa Technology has 4 security vulnerabilities, of which 3 are critical:
【HaoYa Technology|WeenyGenius - Missing Authentication】(CVE-2026-89176, CVSS: 8.8) An unauthenticated attacker on the same network can easily impersonate a student's or teacher's computer; impersonating a student may disrupt the student's normal classroom use, while impersonating a teacher can lead to control of student computers.
【HaoYa Technology|WeenyGenius - Use of Insecure Protocol】(CVE-2026-89177, CVSS: 8.8) Because the communication protocol uses ZMTP Null mode, an unauthenticated attacker on the same network can eavesdrop on packets to obtain the transmitted content.
【HaoYa Technology|WeenyGenius - Origin Validation Error】(CVE-2026-89178, CVSS: 8.8) An unauthenticated attacker on the same network can spoof the teacher side to initiate broadcast packets, causing student computers to attempt to connect to the attacker.
【HaoYa Technology|WeenyGenius - Missing Support for Integrity Check】(CVE-2026-89179, CVSS: 4.3) After capturing a student's connection packets, an unauthenticated attacker on the same network can resend the packets to forge the appearance that the student is still connected.