【Vulnerability Alert】Hao Ya Technology|WeenyGenius - Contains Three Critical Cybersecurity Vulnerabilities

publish date : 2026-09-30 update date : 2026-10-02

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026091808090404 Publication Time 2026-09-18 08:37:05
Incident Type ANA-Vulnerability Alert Discovery Time 2026-09-18 08:37:05
Impact Level Low  
[Subject]
【Vulnerability Alert】Hao Ya Technology|WeenyGenius - Contains Three Critical Cybersecurity Vulnerabilities
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000018

Hao Ya Technology's WeenyGenius contains four security vulnerabilities, including three critical cybersecurity vulnerabilities:

【Hao Ya Technology|WeenyGenius - Missing Authentication】(CVE-2026-89176, CVSS: 8.8) An unauthenticated attacker on the same network can easily impersonate a student or teacher computer. If a student computer is impersonated, normal classroom use by the student may be affected; if a teacher computer is impersonated, the attacker may control student computers.

【Hao Ya Technology|WeenyGenius - Use of Insecure Protocol】(CVE-2026-89177, CVSS: 8.8) Because the communication protocol uses ZMTP Null mode, an unauthenticated attacker on the same network may capture and monitor packets to obtain transmitted content.

【Hao Ya Technology|WeenyGenius - Origin Validation Error】(CVE-2026-89178, CVSS: 8.8) An unauthenticated attacker on the same network may impersonate the teacher side and initiate broadcast packets, causing student computers to attempt to establish connections with the attacker.

【Hao Ya Technology|WeenyGenius - Missing Support for Integrity Check】(CVE-2026-89179, CVSS: 4.3) After intercepting a student's connection packet, an unauthenticated attacker on the same network may replay the packet to create the false appearance that the student is still connected.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

WeenyGenius version 12.2.031 and earlier

[Recommended Actions]

Update to version 12.3.033 or later.

[Reference]

https://www.twcert.org.tw/tw/cp-132-11201-658c0-1.html

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center