# CVE-2026-89177

## Summary

- **CVE ID:** CVE-2026-89177
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-757
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 11, 2026

## Description

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.

## Affected Products

- Howyar — WeenyGenius (0)

## References

- [CNA](https://www.twcert.org.tw/tw/cp-132-11201-658c0-1.html)
- [CNA](https://www.twcert.org.tw/en/cp-139-11200-ffc3c-2.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 13.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._