CVE-2026-89177
WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- CWE
- CWE-757
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- Howyar WeenyGenius
Weakness type
Related vulnerabilities
- CVE-2026-72889 — Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify
- CVE-2026-72887 — Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token
- CVE-2026-18691 — Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure
- CVE-2026-55953 — TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication
- CVE-2026-4942 — IBM i is Affected by Algorithm Downgrade in Transport Layer Security []
- CVE-2026-53712 — SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithms
- CVE-2026-48747 — Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
- CVE-2026-54780 — CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass