
ماسح استغلال وتشخيص لثغرة تنفيذ الأوامر عن بُعد (RCE) غير المصادق عليها في Weaver E-cology، يستهدف نقطة نهاية dubboApi للتصحيح. يتضمن إثبات المفهوم (PoC)، وسكربت Nmap NSE، وإرشادات المعالجة.
يحتوي Weaver E-cology 10.0 (قبل الإصدار 20260312) على ثغرة حرجة لتنفيذ كود عن بُعد غير مصادق عليها في نقطة النهاية /papi/esearch/data/devops/dubboApi/debug/method. يمكن للمهاجمين حقن أوامر عشوائية عبر معاملات POST interfaceName و methodName دون مصادقة، مما يحقق اختراقاً كاملاً للنظام. تم رصد استغلال نشط منذ 2026-03-31 من قبل مؤسسة Shadowserver.
الخطر السريع: CVSS 9.3 - غير مصادق عليه تماماً، لا يتطلب تفاعل المستخدم، نقطة نهاية قابلة للوصول عبر الشبكة تؤدي مباشرة إلى تنفيذ كود.
Weaver E-cology هو أحد أكثر منصات الأتمتة المكتبية (OA) والتعاون المؤسسي انتشاراً في الصين. تم تطويره بواسطة مجموعة Fanwei، ويُستخدم على نطاق واسع في:
يوفر E-cology حلولاً مؤسسية شاملة تشمل:
تتراوح عمليات نشر E-cology عادةً من مئات إلى آلاف المستخدمين لكل مؤسسة. تُعد المنصة مكوناً بنيوياً حاسماً للعديد من المؤسسات، مما يجعل الثغرات فيها ذات تأثير بالغ الخطورة.
توجد الثغرة في نقطة تصحيح dubboApi، والتي يُرجح أنها تُركت قابلة للوصول لأغراض التطوير واستكشاف الأخطاء. تسمح نقطة النهاية بالاستدعاء المباشر لطرق عشوائية عبر إطار عمل Dubbo RPC دون التحقق المناسب من المدخلات أو فحوصات المصادقة.
نمط الكود المعرض:``` POST /papi/esearch/data/devops/dubboApi/debug/method HTTP/1.1 Host: target.com Content-Type: application/json
{ "interfaceName": "com.weaver.rpc.InvokeCommand", "methodName": "executeCommand", "parameters": ["id", "whoami", "cat /etc/passwd"] }
التطبيق يعالج هذه المعاملات مباشرة ويمررها إلى مساعدات تنفيذ أوامر RPC دون:
- التحقق من المصادقة
- التحقق من صحة الإدخال/تنقيته
- فرض قائمة بيضاء للطرق
- فحص أنواع المعاملات
وهذا يسمح للمهاجمين بتحديد طرق واجهة Dubbo عشوائية تنفذ أوامر النظام.
### مخطط تدفق الهجوم```
Internet Attacker
|
| Sends unauthenticated POST request
| with malicious interfaceName/methodName
v
Weaver E-cology HTTP Server (port 80/443)
|
| No authentication check
| No authorization validation
v
/papi/esearch/data/devops/dubboApi/debug/method endpoint
|
| Direct parameter pass-through to Dubbo RPC layer
v
Dubbo RPC Framework (unvalidated interface invocation)
|
| Resolves arbitrary interface methods
| Attacker-controlled method name injection
v
Command Execution Helpers (vulnerable classes)
|
| Direct OS command execution via Runtime.exec()
| or similar OS command invocation mechanisms
v
System Command Execution
|
| Complete code execution as Weaver service user
| (typically root or high-privilege account)
|
+-> Read sensitive files (/etc/passwd, configs)
+-> Execute arbitrary binaries
+-> Create reverse shells
+-> Exfiltrate data
+-> Establish persistence
v
Complete System Compromise
مسار نقطة النهاية: /papi/esearch/data/devops/dubboApi/debug/method
طريقة HTTP: POST
المصادقة المطلوبة: لا شيء (بدون مصادقة)
الترويسات المطلوبة: ترويسات HTTP القياسية (لا تتطلب رموزًا خاصة أو ملفات تعريف ارتباط)
معاملات جسم الطلب:
Internet | v Firewall (often misconfigured or open for "accessibility") | v Web Server (port 80/443) | +--------> HTTP Request to any path | v Route Dispatcher | +---> /login/Login.jsp > Requires authentication | +---> /wui/index.html > Requires authentication | +---> /papi/esearch/data/devops/dubboApi/debug/method | +---> UNPROTECTED - No authentication check! | v Dubbo RPC Invoker (unrestricted method invocation) | v OS Command Execution | v System Compromise (RCE as web user)
### بنية نشر Weaver النموذجية```
Corporate Network
=================
Internet > Firewall (port 80/443 open for E-cology)
|
v
Load Balancer (optional)
|
+---------+---------+
| | |
v v v
Node1 Node2 Node3
Web Web Web
Server Server Server
| | |
+----------+----+----+
|
v
Shared Storage
(Documents/Config)
|
v
Database Server
(MySQL/Oracle)
Each Web Server has:
- Weaver E-cology Java application
- Embedded Tomcat/JBoss container
- Dubbo RPC framework
- VULNERABLE /papi/esearch/data/devops/dubboApi/debug/method
endpoint (pre-patch)
تستغل دولة أو مجموعة إجرامية عمليات نشر E-cology في الوكالات الحكومية من أجل:
يخترق المهاجمون حالات E-cology في البنوك أو المؤسسات المالية من أجل:
تُستخدم حالات E-cology المخترقة كنقاط ارتكاز من أجل:
ملاحظة: قد تكون إصدارات أخرى متأثرة. لم تصدر Weaver معلومات شاملة حول توافق الإصدارات. يجب على المؤسسات اختبار التصحيحات بدقة قبل النشر.
اسم الملف: CVE-2026-22679_Weaver_Ecology_RCE_detector.py
الوصف: سكربت اكتشاف آمن وغير مدمر يحدد حالات Weaver E-cology الضعيفة عن طريق التحقق من إمكانية الوصول إلى نقطة النهاية.```python #!/usr/bin/env python3 """ CVE-2026-22679 Weaver E-cology RCE Detection Scanner Detects vulnerable dubboApi debug endpoint exposure Author: Kerem Oruc (@keraattin) """
import requests import argparse import sys from datetime import datetime from urllib.parse import urljoin import json
class WeaverEcologyScanner: def init(self, timeout=10, verify_ssl=False): self.timeout = timeout self.verify_ssl = verify_ssl self.vulnerable_endpoint = "/papi/esearch/data/devops/dubboApi/debug/method" self.weaver_identifiers = [ "/login/Login.jsp", "/wui/index.html", "/UploadFiles/", ]
def is_weaver_ecology(self, base_url):
"""Identify if target is Weaver E-cology instance"""
for path in self.weaver_identifiers:
try:
url = urljoin(base_url, path)
response = requests.get(
url,
timeout=self.timeout,
verify=self.verify_ssl,
allow_redirects=False
)
if response.status_code in [200, 302, 301]:
return True
except:
continue
return False
def check_vulnerability(self, base_url):
"""Check if dubboApi debug endpoint is accessible"""
try:
url = urljoin(base_url, self.vulnerable_endpoint)
# Test with GET request
response = requests.get(
url,
timeout=self.timeout,
verify=self.verify_ssl,
allow_redirects=False
)
# 200 (success), 405 (method not allowed), or 400 (bad request)
# all indicate endpoint exists
if response.status_code in [200, 400, 405]:
return True, response.status_code
# Test with POST request as fallback
response = requests.post(
url,
json={},
timeout=self.timeout,
verify=self.verify_ssl,
allow_redirects=False
)
if response.status_code in [200, 400, 405]:
return True, response.status_code
return False, response.status_code
except requests.exceptions.RequestException:
return False, None
def scan_target(self, base_url):
"""Scan single target"""
result = {
"target": base_url,
"timestamp": datetime.utcnow().isoformat() + "Z",
"is_weaver": False,
"vulnerable": False,
"endpoint_status": None,
"risk_level": "LOW"
}
# Normalize URL
if not base_url.startswith(("http://", "https://")):
base_url = "http://" + base_url
# Check if Weaver E-cology
is_weaver = self.is_weaver_ecology(base_url)
result["is_weaver"] = is_weaver
if not is_weaver:
result["risk_level"] = "LOW"
return result
# Check vulnerability
is_vulnerable, status_code = self.check_vulnerability(base_url)
result["endpoint_status"] = status_code
result["vulnerable"] = is_vulnerable
if is_vulnerable:
result["risk_level"] = "CRITICAL"
else:
result["risk_level"] = "UNKNOWN"
return result
def format_report(self, results):
"""Format scan results for display"""
report = []
report.append("\n[*] CVE-2026-22679 Weaver E-cology RCE Detection Scanner")
report.append(f"[*] Scanning {len(results)} target(s)...")
report.append("[*] Detection method: dubboApi debug endpoint accessibility check")
report.append(f"[*] Endpoint: {self.vulnerable_endpoint}")
report.append("[*] NOTE: No commands are executed. Safe, non-destructive scan.\n")
report.append("=" * 70)
for result in results:
report.append(f"\nTarget: {result['target']}")
report.append(f"Scan Time: {result['timestamp']}")
report.append(f"Risk Level: {result['risk_level']}")
report.append("=" * 70)
report.append(f" Is Weaver E-cology: {'YES' if result['is_weaver'] else 'NO'}")
report.append(f" Debug Endpoint: {'ACCESSIBLE' if result['vulnerable'] else 'NOT ACCESSIBLE'}")
report.append(f" Endpoint HTTP Status: {result['endpoint_status']}")
report.append(f" Vulnerable: {'YES' if result['vulnerable'] else 'NO'}")
if result["vulnerable"]:
report.append("")
report.append(" *** CRITICAL: dubboApi debug endpoint is exposed! ***")
report.append(" *** Unauthenticated RCE via interfaceName/methodName injection ***")
report.append(f" *** Endpoint: {self.vulnerable_endpoint} ***")
report.append(" *** Update to build 20260312 or block this endpoint immediately ***")
report.append("\n" + "=" * 70)
return "\n".join(report)
def main(): parser = argparse.ArgumentParser( description="CVE-2026-22679 Weaver E-cology RCE Detection Scanner" ) parser.add_argument("targets", nargs="+", help="Target URL(s) to scan (e.g., http://target.com)") parser.add_argument("--timeout", type=int, default=10, help="Request timeout in seconds") parser.add_argument("--no-verify-ssl", action="store_true", help="Disable SSL verification")
args = parser.parse_args()
scanner = WeaverEcologyScanner(timeout=args.timeout, verify_ssl=not args.no_verify_ssl)
results = []
for target in args.targets:
result = scanner.scan_target(target)
results.append(result)
print(scanner.format_report(results))
# Exit with error if any vulnerabilities found
if any(r["vulnerable"] for r in results):
sys.exit(1)
sys.exit(0)
if name == "main": main()
**أمثلة الاستخدام:**```bash
# Scan single target
python3 CVE-2026-22679_Weaver_Ecology_RCE_detector.py http://target.com
# Scan multiple targets
python3 CVE-2026-22679_Weaver_Ecology_RCE_detector.py http://target1.com http://target2.com
# Scan with custom timeout
python3 CVE-2026-22679_Weaver_Ecology_RCE_detector.py http://target.com --timeout 5
# Scan with SSL verification disabled
python3 CVE-2026-22679_Weaver_Ecology_RCE_detector.py https://target.com --no-verify-ssl
مثال على الإخراج:``` [] CVE-2026-22679 Weaver E-cology RCE Detection Scanner [] Scanning 1 target(s)... [] Detection method: dubboApi debug endpoint accessibility check [] Endpoint: /papi/esearch/data/devops/dubboApi/debug/method [*] NOTE: No commands are executed. Safe, non-destructive scan.
Is Weaver E-cology: YES Debug Endpoint: ACCESSIBLE Endpoint HTTP Status: 200 Vulnerable: YES
*** CRITICAL: dubboApi debug endpoint is exposed! *** *** Unauthenticated RCE via interfaceName/methodName injection *** *** Endpoint: /papi/esearch/data/devops/dubboApi/debug/method *** *** Update to build 20260312 or block this endpoint immediately ***
======================================================================
### سكربت Nmap NSE
**اسم الملف:** `CVE-2026-22679_Weaver_Ecology_RCE.nse`
**الوصف:** سكربت Nmap NSE للكشف عن الثغرات الأمنية ومتكامل مع سير عمل Nmap.```lua
-- CVE-2026-22679 Weaver E-cology RCE Detection Script
-- Detects vulnerable dubboApi debug endpoint exposure
-- Author: Kerem Oruc (@keraattin)
local http = require "http"
local shortport = require "shortport"
local stdnse = require "stdnse"
local vulns = require "vulns"
description = [[
Detects Weaver E-cology instances vulnerable to CVE-2026-22679.
This vulnerability allows unauthenticated remote code execution through
the exposed dubboApi debug endpoint at /papi/esearch/data/devops/dubboApi/debug/method
]]
author = "Kerem Oruc (@keraattin)"
license = "Same as Nmap--See https://nmap.org/COPYING"
categories = {"vuln", "safe"}
portrule = shortport.http
local VULNERABLE_ENDPOINT = "/papi/esearch/data/devops/dubboApi/debug/method"
local WEAVER_IDENTIFIERS = {
"/login/Login.jsp",
"/wui/index.html",
"/UploadFiles/"
}
local function is_weaver_ecology(host, port)
for _, path in ipairs(WEAVER_IDENTIFIERS) do
local response = http.get(host, port, path)
if response.status and response.status >= 200 and response.status < 400 then
return true
end
end
return false
end
local function check_vulnerability(host, port)
local response = http.get(host, port, VULNERABLE_ENDPOINT)
if response.status then
-- 200 (OK), 400 (Bad Request), 405 (Method Not Allowed)
-- all indicate the endpoint exists (unpatched)
if response.status == 200 or response.status == 400 or response.status == 405 then
return true, response.status
end
end
-- Try POST as fallback
local response = http.post(host, port, VULNERABLE_ENDPOINT, nil, {}, "")
if response.status then
if response.status == 200 or response.status == 400 or response.status == 405 then
return true, response.status
end
end
return false, response.status or "unknown"
end
action = function(host, port)
local vuln_table = {
title = "Weaver E-cology Unauthenticated RCE (CVE-2026-22679)",
state = vulns.STATE.UNKNOWN,
risk_level = "CRITICAL",
IDS = {
CVE = "CVE-2026-22679",
CWE = "CWE-94"
},
description = [[
The dubboApi debug endpoint is exposed without authentication.
An attacker can send POST requests with crafted parameters to
achieve remote code execution through parameter injection.
]],
references = {
"https://nvd.nist.gov/vuln/detail/CVE-2026-22679",
},
dates = {
disclosure = {year = 2026, month = 3, day = 31},
discovery = {year = 2026, month = 3, day = 12}
}
}
local vuln_report = vulns.Report:new(VULNERABLE_ENDPOINT, host, port)
-- Check if target is Weaver E-cology
if not is_weaver_ecology(host, port) then
vuln_table.state = vulns.STATE.NOT_VULN
return vuln_report:make_output(vuln_table)
end
-- Check if vulnerable endpoint is accessible
local is_vulnerable, status_code = check_vulnerability(host, port)
if is_vulnerable then
vuln_table.state = vulns.STATE.VULNERABLE
vuln_table.extra_info = string.format(
"Debug endpoint accessible at %s (HTTP %d)",
VULNERABLE_ENDPOINT,
status_code
)
else
vuln_table.state = vulns.STATE.NOT_VULN
end
return vuln_report:make_output(vuln_table)
end
أمثلة الاستخدام:```bash
nmap -p 80 --script CVE-2026-22679_Weaver_Ecology_RCE.nse target.com
nmap -p 80,443,8080,8443 --script CVE-2026-22679_Weaver_Ecology_RCE.nse target.com
nmap -p 80 --script CVE-2026-22679_Weaver_Ecology_RCE.nse 10.0.0.0/24
nmap -p 80 --script CVE-2026-22679_Weaver_Ecology_RCE.nse -v target.com
nmap -p 80 --script http-title,http-headers,CVE-2026-22679_Weaver_Ecology_RCE.nse target.com
**مثال على الإخراج:**```
PORT STATE SERVICE
80/tcp open http
| CVE-2026-22679_Weaver_Ecology_RCE:
| VULNERABLE:
| Weaver E-cology Unauthenticated RCE (CVE-2026-22679)
| State: VULNERABLE
| Risk level: CRITICAL
| Debug endpoint: accessible at /papi/esearch/data/devops/dubboApi/debug/method
| Description:
| The dubboApi debug endpoint is exposed without authentication.
| An attacker can send POST requests with crafted parameters to
| achieve remote code execution. Update to build 20260312.
| Discovery Date: 2026-03-12
| Disclosure Date: 2026-03-31
| IDs:
| CVE: CVE-2026-22679
| CWE: CWE-94 (Code Injection)
| References:
|_ https://nvd.nist.gov/vuln/detail/CVE-2026-22679
/papi/esearch/data/devops/dubboApi/debug/methodinterfaceName أو methodNameسجلات الوصول لخادم الويب:``` POST /papi/esearch/data/devops/dubboApi/debug/method HTTP/1.1 200 - POST /papi/esearch/data/devops/dubboApi/debug/method HTTP/1.1 405 - GET /papi/esearch/data/devops/dubboApi/debug/method HTTP/1.1 405 -
**سجلات التطبيق:**
- استثناءات أو أخطاء متعلقة باستدعاء RPC الخاص بـ Dubbo
- تحذيرات حول معاملات غير مُتحقق منها في سجلات إطار عمل RPC
- ClassNotFoundException أو فشل في استدعاء الدوال
- محاولات غير متوقعة لحل الواجهات
### مؤشرات على مستوى المضيف
- عمليات فرعية غير متوقعة تم إنشاؤها من عملية Weaver Java
- حسابات مستخدمين جديدة تم إنشاؤها على النظام
- اتصالات شبكة غير متوقعة من خدمة Weaver
- تعديل ملفات إعدادات Weaver
- وجود webshells في أدلة Weaver
- كتابة ملفات غير معتادة إلى أدلة النظام
- إدخالات مشبوهة في cronjob أو الخدمات
### مؤشرات على مستوى نظام الملفات
- ملفات غير متوقعة في `/tmp/` أو `/var/tmp/`
- ملفات JAR الخاصة بـ Weaver أو ملفات الإعدادات المعدلة
- سكربتات شل جديدة في أدلة يمكن الوصول إليها عبر الويب
- وجود أسماء ملفات webshell شائعة (shell.jsp، cmd.jsp، إلخ.)
---
## المعالجة
### إجراءات فورية (0-24 ساعة)
1. **تعطيل الوصول إلى نقطة نهاية التصحيح عبر الشبكة**
أضف قاعدة جدار حماية لمنع الوصول إلى نقطة النهاية الضعيفة: ```
# iptables example
iptables -I INPUT -p tcp --dport 80 -m string --string "/papi/esearch/data/devops/dubboApi" --algo bm -j DROP
# nginx example
location /papi/esearch/data/devops/dubboApi {
return 403;
}
# Apache example
<Location "/papi/esearch/data/devops/dubboApi">
Deny from all
</Location>
مراقبة الاستغلال النشط
تقييد الوصول إلى الشبكة
تطبيق التصحيح الرسمي
قم بالتحديث إلى إصدار Weaver E-cology build 20260312 أو أحدث: ```bash
cp -r /opt/ecology /opt/ecology.backup.20260415
/opt/ecology/bin/upgrade.sh --version 20260312
curl -X POST http://localhost/papi/esearch/data/devops/dubboApi/debug/method
مراجعة سجلات الوصول
إجراء فحص جنائي للمضيف
تقييم شامل للنظام
تنفيذ تقسيم الشبكة
التحصين
تحديث المراقبة الأمنية
Kerem Oruc (@keraattin)
إخلاء المسؤولية: يتم توفير هذه المعلومات لأغراض تعليمية وأمنية دفاعية فقط. الوصول غير المصرح به إلى أنظمة الكمبيوتر غير قانوني. احصل دائمًا على التصريح المناسب قبل اختبار أو الوصول إلى الأنظمة التي لا تملكها.
آخر تحديث: 2026-04-15
| الجانب | التفاصيل |
|---|
| معرف CVE | CVE-2026-22679 |
| درجة CVSS | 9.3 (حرجة) |
| متجه CVSS | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CWE | CWE-94 (حقن كود) |
| البائع | Weaver (Fanwei) |
| المنتج | E-cology 10.0 |
| نوع الثغرة | تنفيذ كود عن بُعد غير مصادق عليه (RCE) |
| نقطة النهاية المتأثرة | /papi/esearch/data/devops/dubboApi/debug/method |
| متجه الهجوم | شبكة / HTTP POST |
| المصادقة المطلوبة | لا شيء |
| الإصدارات المتأثرة | إصدارات 10.0 قبل الإصدار 20260312 |
| الإصدار المُصلَح | الإصدار 20260312 (صدر في 2026-03-12) |
| الاستغلال النشط | منذ 2026-03-31 (مؤسسة Shadowserver) |
| طريقة التصحيح | الإزالة الكاملة لنقطة النهاية المعرضة |
| المعامل | النوع | الوصف | مثال |
|---|
interfaceName | String | اسم فئة واجهة RPC (يُتحكم فيه من قبل المهاجم) | com.weaver.rpc.InvokeCommand |
methodName | String | اسم الطريقة المراد استدعاؤها (يُتحكم فيه من قبل المهاجم) | executeCommand |
parameters | Array | معاملات الطريقة التي تُمرَّر مباشرة إلى منطق التنفيذ | ["id"] |
| مجال التأثير | الخطورة | التفاصيل |
|---|
| السرية | حرجة | وصول غير مصادق عليه إلى جميع بيانات النظام والمستندات وبيانات اعتماد المستخدمين ومحتويات قاعدة البيانات |
| السلامة | حرجة | القدرة على تعديل الملفات والمستندات وسجلات قاعدة البيانات وإعدادات النظام |
| التوفر | حرجة | إيقاف تشغيل النظام واستنزاف الموارد وتدمير البيانات وتعطيل الخدمات |
| النطاق | متغير | عادةً ما يعمل مستخدم خدمة Weaver بصلاحيات الجذر أو بصلاحيات عالية الامتياز؛ اختراق كامل للنظام |
| الإصدار | نطاق البناء | الحالة | التصحيح المتاح |
|---|
| 10.0 | < 20260312 | ضعيف | نعم |
| 10.0 | >= 20260312 | مُصحح | غير متاح (تمت إزالة نقطة النهاية) |
| 9.x والإصدارات الأقدم | الكل | غير معروف | تحقق مع المورد |