PT-2026-30819 · Fanwei · Weaver E-Cology
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Weaver (Fanwei) E-cology versions prior to 20260312
Description
An unauthenticated remote code execution flaw exists due to exposed debug functionality. Attackers can execute arbitrary system commands by sending crafted POST requests to the '/papi/esearch/data/devops/dubboApi/debug/method' endpoint. The attack is carried out by manipulating the
interfaceName and methodName parameters to reach command-execution helpers. This issue has been actively exploited in the wild since mid-March, with evidence first observed by the Shadowserver Foundation on 2026-03-31 (UTC).Recommendations
Update Weaver (Fanwei) E-cology to version 20260312 or later.
As a temporary workaround, restrict access to the '/papi/esearch/data/devops/dubboApi/debug/method' endpoint to minimize the risk of exploitation.
Exploit
Fix
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Weaver E-Cology