【Vulnerability Alert】Hao Ya Technology|WeenyGenius - Contains Three Critical Cybersecurity Vulnerabilities
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026091808090404 | Publication Time | 2026-09-18 08:37:05 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-18 08:37:05 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Hao Ya Technology|WeenyGenius - Contains Three Critical Cybersecurity Vulnerabilities |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000018 Hao Ya Technology's WeenyGenius contains four security vulnerabilities, including three critical cybersecurity vulnerabilities: 【Hao Ya Technology|WeenyGenius - Missing Authentication】(CVE-2026-89176, CVSS: 8.8) An unauthenticated attacker on the same network can easily impersonate a student or teacher computer. If a student computer is impersonated, normal classroom use by the student may be affected; if a teacher computer is impersonated, the attacker may control student computers. 【Hao Ya Technology|WeenyGenius - Use of Insecure Protocol】(CVE-2026-89177, CVSS: 8.8) Because the communication protocol uses ZMTP Null mode, an unauthenticated attacker on the same network may capture and monitor packets to obtain transmitted content. 【Hao Ya Technology|WeenyGenius - Origin Validation Error】(CVE-2026-89178, CVSS: 8.8) An unauthenticated attacker on the same network may impersonate the teacher side and initiate broadcast packets, causing student computers to attempt to establish connections with the attacker. 【Hao Ya Technology|WeenyGenius - Missing Support for Integrity Check】(CVE-2026-89179, CVSS: 4.3) After intercepting a student's connection packet, an unauthenticated attacker on the same network may replay the packet to create the false appearance that the student is still connected. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
WeenyGenius version 12.2.031 and earlier |
|||
|
[Recommended Actions] Update to version 12.3.033 or later. |
|||
|
[Reference] |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





