| TVN ID | TVN-202609005 |
|---|---|
| CVE ID | CVE-2026-89176, CVE-2026-89177, CVE-2026-89178, CVE-2026-89179 |
| CVSS | 【CVE-2026-89176】 8.7 (High) CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 8.8 (High) CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 【CVE-2026-89177】 8.7 (High) CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 8.8 (High) CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 【CVE-2026-89178】 8.7 (High) CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 8.8 (High) CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 【CVE-2026-89179】 5.3 (Medium) CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N 4.3 (Medium) CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
| Affected Products | WeenyGenius version 12.2.031 and earlier |
| Description | 【CVE-2026-89176(Missing Authentication)】 Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can disrupt normal classroom operations, whereas impersonating a teacher can induce student computers to initiate connections, thereby gaining remote control over the student endpoints. 【CVE-2026-89177(Use of Insecure Protocol)】 Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations. 【CVE-2026-89178(Origin Validation Error)】 Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker. 【CVE-2026-89179(Missing Support for Integrity Check)】 Unauthenticated attackers on the same network can intercept a student's connection packet and replay it, thereby forging the appearance that the student remains connected. |
| Solution | Update to version 12.3.033 or later. |
| Credit | 鄭凱駿 |
| Public Date | 2026-09-11 |
