CVE-2026-22679 is a critical unauthenticated remote code execution vulnerability affecting Weaver (Fanwei) E-cology 10.0 versions prior to 20260312. The flaw exists in the /papi/esearch/data/devops/dubboApi/debug/method endpoint, where exposed debug functionality can be invoked via crafted POST requests supplying attacker-controlled interfaceName and methodName parameters. Successful exploitation allows attackers to reach command-execution helpers and execute arbitrary system commands, leading to full confidentiality, integrity, and availability compromise. The issue is tracked as CWE-306 (missing authentication) and has a CVSSv3.1 base score of 9.8 (Critical). Public evidence of exploitation was first observed by Shadowserver on 2026-03-31 (UTC).
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

