:::

【資安漏洞預警】昊亞科技|WeenyGenius - 存在3個重大資安漏洞
【Security Vulnerability Alert】Howyar|WeenyGenius - 3 Critical Security Vulnerabilities

公告類別:行政公告
發佈日期:2026/09/24 至 2027/03/24
點閱數:57

轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202609-00000018

[內容說明]
昊亞科技產品WeenyGenius存在4個安全性漏洞,其中包含3個重大資安漏洞:
【昊亞科技|WeenyGenius - Missing Authentication】(CVE-2026-89176,CVSS:8.8) 未經身分鑑別之同網域攻擊者可輕易冒用學生或教師電腦,若冒用學生可影響學生課堂正常使用,冒用老師則可控制學生電腦。
【昊亞科技|WeenyGenius - Use of Insecure Protocol 】(CVE-2026-89177,CVSS:8.8) 由於通訊協定採用ZMTP Null模式,未經身分鑑別之同網域攻擊者可側錄監聽封包以取得傳輸內容。
【昊亞科技|WeenyGenius - Origin Validation Error 】(CVE-2026-89178,CVSS:8.8) 未經身分鑑別之同網域攻擊者可偽冒老師端發起廣播封包,使學生端電腦嘗試與攻擊者建立連線。
【昊亞科技|WeenyGenius - Missing Support for Integrity Check 】(CVE-2026-89179,CVSS:4.3) 未經身分鑑別之同網域攻擊者於攜截學生連線封包後,可重送該封包,偽造該學生仍處於連線狀態之假象。

[影響平台]
WeenyGenius 12.2.031(含)以前版本

[建議措施]
更新至 12.3.033(含)以後版本

[參考資料]
1. https://www.twcert.org.tw/tw/cp-132-11201-658c0-1.html
Forwarded from Taiwan Computer Emergency Response Team / Coordination Center Security Information Alert TWCERTCC-200-202609-00000018

[Content Description]
Howyar's product WeenyGenius contains 4 security vulnerabilities, including 3 critical security vulnerabilities:
【Howyar|WeenyGenius - Missing Authentication】(CVE-2026-89176, CVSS:8.8) Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can disrupt normal classroom operations, whereas impersonating a teacher can control student computers.
【Howyar|WeenyGenius - Use of Insecure Protocol 】(CVE-2026-89177, CVSS:8.8) Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to obtain transmitted data.
【Howyar|WeenyGenius - Origin Validation Error 】(CVE-2026-89178, CVSS:8.8) Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker.
【Howyar|WeenyGenius - Missing Support for Integrity Check 】(CVE-2026-89179, CVSS:4.3) Unauthenticated attackers on the same network can intercept a student's connection packet and replay it, thereby forging the appearance that the student remains connected.

[Affected Platforms]
WeenyGenius versions 12.2.031 (inclusive) and earlier

[Recommended Measures]
Update to version 12.3.033 (inclusive) or later.

[References]
1. https://www.twcert.org.tw/tw/cp-132-11201-658c0-1.html

相關附件

※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。

返回列表