Posting Date: 2026/09/21
【Vulnerability Alert】HaoYa Technology|WeenyGenius - 3 Critical Security Vulnerabilities
- Subject:【Vulnerability Alert】HaoYa Technology|WeenyGenius - 3 Critical Security Vulnerabilities
- Description:
- Forwarded from TWCERT/CC Security Advisory TWCERTCC-200-202609-00000018
- The WeenyGenius product by HaoYa Technology has 4 security vulnerabilities, of which 3 are critical:
- 【HaoYa Technology|WeenyGenius - Missing Authentication】(CVE-2026-89176, CVSS: 8.8) An unauthenticated attacker on the same network can easily impersonate a student's or teacher's computer; impersonating a student may disrupt the student's normal classroom use, while impersonating a teacher can lead to control of student computers.
- 【HaoYa Technology|WeenyGenius - Use of Insecure Protocol】(CVE-2026-89177, CVSS: 8.8) Because the communication protocol uses ZMTP Null mode, an unauthenticated attacker on the same network can eavesdrop on packets to obtain the transmitted content.
- 【HaoYa Technology|WeenyGenius - Origin Validation Error】(CVE-2026-89178, CVSS: 8.8) An unauthenticated attacker on the same network can spoof the teacher side to initiate broadcast packets, causing student computers to attempt to connect to the attacker.
- 【HaoYa Technology|WeenyGenius - Missing Support for Integrity Check】(CVE-2026-89179, CVSS: 4.3) After capturing a student's connection packets, an unauthenticated attacker on the same network can resend the packets to forge the appearance that the student is still connected.
- Affected Platforms:
- WeenyGenius 12.2.031 and earlier
- Recommended Actions:
- Update to 12.3.033 or later
- References:
Computer and Communication Center
Network System Division