PT-2026-30819 · Fanwei · Weaver E-Cology

·

CVE-2026-22679

·

Published

2026-04-07

·

Updated

2026-06-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Weaver (Fanwei) E-cology versions prior to 20260312
Description An unauthenticated remote code execution flaw exists due to exposed debug functionality. Attackers can execute arbitrary system commands by sending crafted POST requests to the '/papi/esearch/data/devops/dubboApi/debug/method' endpoint. The attack is carried out by manipulating the interfaceName and methodName parameters to reach command-execution helpers. This issue has been actively exploited in the wild since mid-March, with evidence first observed by the Shadowserver Foundation on 2026-03-31 (UTC).
Recommendations Update Weaver (Fanwei) E-cology to version 20260312 or later. As a temporary workaround, restrict access to the '/papi/esearch/data/devops/dubboApi/debug/method' endpoint to minimize the risk of exploitation.

Exploit

Fix

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22679

Affected Products

Weaver E-Cology