PT-2026-30819 · Fanwei · Weaver E-Cology

Published

2026-04-07

·

Updated

2026-05-04

·

CVE-2026-22679

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Weaver (Fanwei) E-cology versions prior to 20260312
Description Weaver (Fanwei) E-cology 10.0 contains an unauthenticated remote code execution issue in the /papi/esearch/data/devops/dubboApi/debug/method endpoint. Attackers can execute arbitrary commands by invoking exposed debug functionality. This is achieved by crafting POST requests with attacker-controlled interfaceName and methodName parameters to reach command-execution helpers. The Shadowserver Foundation first observed exploitation evidence on 2026-03-31 (UTC).
Recommendations Update Weaver (Fanwei) E-cology to version 20260312 or later.

Exploit

Fix

RCE

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-22679

Affected Products

Weaver E-Cology