GHSA-vg4v-xjcr-x7p5 · Severity: critical — Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code...
Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute arbitrary commands by invoking exposed debug functionality. Attackers can craft POST requests with attacker-controlled interfaceName and methodName parameters to reach command-execution helpers and achieve arbitrary command execution on the system. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-03-31 (UTC).
Conclusion & alert: CVE-2026-22679 is rated Moderate Risk (56/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.30%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-22 | 0.15% | 0.30% | +0.15% |
| 2 | 2026-04-21 | 0.40% | 0.15% | -0.25% |
| 3 | 2026-04-13 | — | 0.40% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.3 | 4.0 | CRITICAL |
|
— | — | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-vg4v-xjcr-x7p5 · Severity: critical — Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code...