
Scanner di exploit e rilevamento RCE non autenticato per Weaver E-cology, che prende di mira l'endpoint di debug dubboApi. Include PoC, script Nmap NSE e indicazioni per la rimediation.
Weaver E-cology 10.0 (precedente alla build 20260312) contiene una vulnerabilità critica di esecuzione remota di codice non autenticata nell'endpoint /papi/esearch/data/devops/dubboApi/debug/method. Gli attaccanti possono iniettare comandi arbitrari tramite i parametri POST interfaceName e methodName senza autenticazione, ottenendo il completo compromesso del sistema. Sfruttamento attivo rilevato dal 2026-03-31 dalla Shadowserver Foundation.
Rischio Rapido: CVSS 9.3 - Completamente non autenticato, nessuna interazione utente richiesta, endpoint accessibile dalla rete che porta direttamente all'esecuzione di codice.
Weaver E-cology è una delle piattaforme enterprise OA (Office Automation) e di collaborazione più ampiamente distribuite in Cina. Sviluppata da Fanwei Group, è ampiamente utilizzata in:
E-cology fornisce soluzioni enterprise complete, tra cui:
Le distribuzioni di E-cology tipicamente variano da centinaia a migliaia di utenti per organizzazione. La piattaforma è un componente infrastrutturale critico per molte organizzazioni, rendendo le vulnerabilità in essa estremamente ad alto impatto.
La vulnerabilità esiste nell'endpoint di debug dubboApi, che probabilmente è stato lasciato accessibile per scopi di sviluppo e risoluzione dei problemi. L'endpoint consente l'invocazione diretta di metodi arbitrari tramite il framework RPC Dubbo senza una corretta validazione degli input o controlli di autenticazione.
Pattern di Codice Vulnerabile:``` POST /papi/esearch/data/devops/dubboApi/debug/method HTTP/1.1 Host: target.com Content-Type: application/json
{ "interfaceName": "com.weaver.rpc.InvokeCommand", "methodName": "executeCommand", "parameters": ["id", "whoami", "cat /etc/passwd"] }
L'applicazione elabora direttamente questi parametri e li passa agli helper di esecuzione dei comandi RPC senza:
- Verifica dell'autenticazione
- Validazione/sanitizzazione dell'input
- Applicazione di una whitelist dei metodi
- Controllo del tipo dei parametri
Ciò consente agli attaccanti di specificare metodi arbitrari dell'interfaccia Dubbo che eseguono comandi di sistema.
### Diagramma del Flusso di Attacco```
Internet Attacker
|
| Sends unauthenticated POST request
| with malicious interfaceName/methodName
v
Weaver E-cology HTTP Server (port 80/443)
|
| No authentication check
| No authorization validation
v
/papi/esearch/data/devops/dubboApi/debug/method endpoint
|
| Direct parameter pass-through to Dubbo RPC layer
v
Dubbo RPC Framework (unvalidated interface invocation)
|
| Resolves arbitrary interface methods
| Attacker-controlled method name injection
v
Command Execution Helpers (vulnerable classes)
|
| Direct OS command execution via Runtime.exec()
| or similar OS command invocation mechanisms
v
System Command Execution
|
| Complete code execution as Weaver service user
| (typically root or high-privilege account)
|
+-> Read sensitive files (/etc/passwd, configs)
+-> Execute arbitrary binaries
+-> Create reverse shells
+-> Exfiltrate data
+-> Establish persistence
v
Complete System Compromise
Percorso dell'Endpoint: /papi/esearch/data/devops/dubboApi/debug/method
Metodo HTTP: POST
Autenticazione Richiesta: Nessuna (zero autenticazione)
Intestazioni Richieste: Intestazioni HTTP standard (nessun token speciale o cookie richiesto)
Parametri del Corpo della Richiesta:
Internet | v Firewall (often misconfigured or open for "accessibility") | v Web Server (port 80/443) | +--------> HTTP Request to any path | v Route Dispatcher | +---> /login/Login.jsp > Requires authentication | +---> /wui/index.html > Requires authentication | +---> /papi/esearch/data/devops/dubboApi/debug/method | +---> UNPROTECTED - No authentication check! | v Dubbo RPC Invoker (unrestricted method invocation) | v OS Command Execution | v System Compromise (RCE as web user)
### Architettura Tipica di Distribuzione di Weaver```
Corporate Network
=================
Internet > Firewall (port 80/443 open for E-cology)
|
v
Load Balancer (optional)
|
+---------+---------+
| | |
v v v
Node1 Node2 Node3
Web Web Web
Server Server Server
| | |
+----------+----+----+
|
v
Shared Storage
(Documents/Config)
|
v
Database Server
(MySQL/Oracle)
Each Web Server has:
- Weaver E-cology Java application
- Embedded Tomcat/JBoss container
- Dubbo RPC framework
- VULNERABLE /papi/esearch/data/devops/dubboApi/debug/method
endpoint (pre-patch)
Uno stato-nazione o un gruppo criminale sfrutta le implementazioni di E-cology presso le agenzie governative per:
Gli attaccanti compromettono le istanze di E-cology presso banche o istituzioni finanziarie per:
Le istanze compromesse di E-cology vengono utilizzate come punti di pivot per:
Nota: Altre versioni potrebbero essere interessate. Weaver non ha rilasciato informazioni complete sulla compatibilità delle versioni. Le organizzazioni dovrebbero testare accuratamente le patch prima della distribuzione.
Nome file: CVE-2026-22679_Weaver_Ecology_RCE_detector.py
Descrizione: Script di rilevamento sicuro e non distruttivo che identifica le istanze vulnerabili di Weaver E-cology verificando l'accessibilità dell'endpoint.```python #!/usr/bin/env python3 """ CVE-2026-22679 Weaver E-cology RCE Detection Scanner Detects vulnerable dubboApi debug endpoint exposure Author: Kerem Oruc (@keraattin) """
import requests import argparse import sys from datetime import datetime from urllib.parse import urljoin import json
class WeaverEcologyScanner: def init(self, timeout=10, verify_ssl=False): self.timeout = timeout self.verify_ssl = verify_ssl self.vulnerable_endpoint = "/papi/esearch/data/devops/dubboApi/debug/method" self.weaver_identifiers = [ "/login/Login.jsp", "/wui/index.html", "/UploadFiles/", ]
def is_weaver_ecology(self, base_url):
"""Identify if target is Weaver E-cology instance"""
for path in self.weaver_identifiers:
try:
url = urljoin(base_url, path)
response = requests.get(
url,
timeout=self.timeout,
verify=self.verify_ssl,
allow_redirects=False
)
if response.status_code in [200, 302, 301]:
return True
except:
continue
return False
def check_vulnerability(self, base_url):
"""Check if dubboApi debug endpoint is accessible"""
try:
url = urljoin(base_url, self.vulnerable_endpoint)
# Test with GET request
response = requests.get(
url,
timeout=self.timeout,
verify=self.verify_ssl,
allow_redirects=False
)
# 200 (success), 405 (method not allowed), or 400 (bad request)
# all indicate endpoint exists
if response.status_code in [200, 400, 405]:
return True, response.status_code
# Test with POST request as fallback
response = requests.post(
url,
json={},
timeout=self.timeout,
verify=self.verify_ssl,
allow_redirects=False
)
if response.status_code in [200, 400, 405]:
return True, response.status_code
return False, response.status_code
except requests.exceptions.RequestException:
return False, None
def scan_target(self, base_url):
"""Scan single target"""
result = {
"target": base_url,
"timestamp": datetime.utcnow().isoformat() + "Z",
"is_weaver": False,
"vulnerable": False,
"endpoint_status": None,
"risk_level": "LOW"
}
# Normalize URL
if not base_url.startswith(("http://", "https://")):
base_url = "http://" + base_url
# Check if Weaver E-cology
is_weaver = self.is_weaver_ecology(base_url)
result["is_weaver"] = is_weaver
if not is_weaver:
result["risk_level"] = "LOW"
return result
# Check vulnerability
is_vulnerable, status_code = self.check_vulnerability(base_url)
result["endpoint_status"] = status_code
result["vulnerable"] = is_vulnerable
if is_vulnerable:
result["risk_level"] = "CRITICAL"
else:
result["risk_level"] = "UNKNOWN"
return result
def format_report(self, results):
"""Format scan results for display"""
report = []
report.append("\n[*] CVE-2026-22679 Weaver E-cology RCE Detection Scanner")
report.append(f"[*] Scanning {len(results)} target(s)...")
report.append("[*] Detection method: dubboApi debug endpoint accessibility check")
report.append(f"[*] Endpoint: {self.vulnerable_endpoint}")
report.append("[*] NOTE: No commands are executed. Safe, non-destructive scan.\n")
report.append("=" * 70)
for result in results:
report.append(f"\nTarget: {result['target']}")
report.append(f"Scan Time: {result['timestamp']}")
report.append(f"Risk Level: {result['risk_level']}")
report.append("=" * 70)
report.append(f" Is Weaver E-cology: {'YES' if result['is_weaver'] else 'NO'}")
report.append(f" Debug Endpoint: {'ACCESSIBLE' if result['vulnerable'] else 'NOT ACCESSIBLE'}")
report.append(f" Endpoint HTTP Status: {result['endpoint_status']}")
report.append(f" Vulnerable: {'YES' if result['vulnerable'] else 'NO'}")
if result["vulnerable"]:
report.append("")
report.append(" *** CRITICAL: dubboApi debug endpoint is exposed! ***")
report.append(" *** Unauthenticated RCE via interfaceName/methodName injection ***")
report.append(f" *** Endpoint: {self.vulnerable_endpoint} ***")
report.append(" *** Update to build 20260312 or block this endpoint immediately ***")
report.append("\n" + "=" * 70)
return "\n".join(report)
def main(): parser = argparse.ArgumentParser( description="CVE-2026-22679 Weaver E-cology RCE Detection Scanner" ) parser.add_argument("targets", nargs="+", help="Target URL(s) to scan (e.g., http://target.com)") parser.add_argument("--timeout", type=int, default=10, help="Request timeout in seconds") parser.add_argument("--no-verify-ssl", action="store_true", help="Disable SSL verification")
args = parser.parse_args()
scanner = WeaverEcologyScanner(timeout=args.timeout, verify_ssl=not args.no_verify_ssl)
results = []
for target in args.targets:
result = scanner.scan_target(target)
results.append(result)
print(scanner.format_report(results))
# Exit with error if any vulnerabilities found
if any(r["vulnerable"] for r in results):
sys.exit(1)
sys.exit(0)
if name == "main": main()
**Esempi di utilizzo:**```bash
# Scan single target
python3 CVE-2026-22679_Weaver_Ecology_RCE_detector.py http://target.com
# Scan multiple targets
python3 CVE-2026-22679_Weaver_Ecology_RCE_detector.py http://target1.com http://target2.com
# Scan with custom timeout
python3 CVE-2026-22679_Weaver_Ecology_RCE_detector.py http://target.com --timeout 5
# Scan with SSL verification disabled
python3 CVE-2026-22679_Weaver_Ecology_RCE_detector.py https://target.com --no-verify-ssl
Esempio di output:``` [] CVE-2026-22679 Weaver E-cology RCE Detection Scanner [] Scanning 1 target(s)... [] Detection method: dubboApi debug endpoint accessibility check [] Endpoint: /papi/esearch/data/devops/dubboApi/debug/method [*] NOTE: No commands are executed. Safe, non-destructive scan.
Is Weaver E-cology: YES Debug Endpoint: ACCESSIBLE Endpoint HTTP Status: 200 Vulnerable: YES
*** CRITICAL: dubboApi debug endpoint is exposed! *** *** Unauthenticated RCE via interfaceName/methodName injection *** *** Endpoint: /papi/esearch/data/devops/dubboApi/debug/method *** *** Update to build 20260312 or block this endpoint immediately ***
======================================================================
### Script NSE per Nmap
**Nome file:** `CVE-2026-22679_Weaver_Ecology_RCE.nse`
**Descrizione:** Script NSE per Nmap per il rilevamento delle vulnerabilità, integrato con i flussi di lavoro di Nmap.```lua
-- CVE-2026-22679 Weaver E-cology RCE Detection Script
-- Detects vulnerable dubboApi debug endpoint exposure
-- Author: Kerem Oruc (@keraattin)
local http = require "http"
local shortport = require "shortport"
local stdnse = require "stdnse"
local vulns = require "vulns"
description = [[
Detects Weaver E-cology instances vulnerable to CVE-2026-22679.
This vulnerability allows unauthenticated remote code execution through
the exposed dubboApi debug endpoint at /papi/esearch/data/devops/dubboApi/debug/method
]]
author = "Kerem Oruc (@keraattin)"
license = "Same as Nmap--See https://nmap.org/COPYING"
categories = {"vuln", "safe"}
portrule = shortport.http
local VULNERABLE_ENDPOINT = "/papi/esearch/data/devops/dubboApi/debug/method"
local WEAVER_IDENTIFIERS = {
"/login/Login.jsp",
"/wui/index.html",
"/UploadFiles/"
}
local function is_weaver_ecology(host, port)
for _, path in ipairs(WEAVER_IDENTIFIERS) do
local response = http.get(host, port, path)
if response.status and response.status >= 200 and response.status < 400 then
return true
end
end
return false
end
local function check_vulnerability(host, port)
local response = http.get(host, port, VULNERABLE_ENDPOINT)
if response.status then
-- 200 (OK), 400 (Bad Request), 405 (Method Not Allowed)
-- all indicate the endpoint exists (unpatched)
if response.status == 200 or response.status == 400 or response.status == 405 then
return true, response.status
end
end
-- Try POST as fallback
local response = http.post(host, port, VULNERABLE_ENDPOINT, nil, {}, "")
if response.status then
if response.status == 200 or response.status == 400 or response.status == 405 then
return true, response.status
end
end
return false, response.status or "unknown"
end
action = function(host, port)
local vuln_table = {
title = "Weaver E-cology Unauthenticated RCE (CVE-2026-22679)",
state = vulns.STATE.UNKNOWN,
risk_level = "CRITICAL",
IDS = {
CVE = "CVE-2026-22679",
CWE = "CWE-94"
},
description = [[
The dubboApi debug endpoint is exposed without authentication.
An attacker can send POST requests with crafted parameters to
achieve remote code execution through parameter injection.
]],
references = {
"https://nvd.nist.gov/vuln/detail/CVE-2026-22679",
},
dates = {
disclosure = {year = 2026, month = 3, day = 31},
discovery = {year = 2026, month = 3, day = 12}
}
}
local vuln_report = vulns.Report:new(VULNERABLE_ENDPOINT, host, port)
-- Check if target is Weaver E-cology
if not is_weaver_ecology(host, port) then
vuln_table.state = vulns.STATE.NOT_VULN
return vuln_report:make_output(vuln_table)
end
-- Check if vulnerable endpoint is accessible
local is_vulnerable, status_code = check_vulnerability(host, port)
if is_vulnerable then
vuln_table.state = vulns.STATE.VULNERABLE
vuln_table.extra_info = string.format(
"Debug endpoint accessible at %s (HTTP %d)",
VULNERABLE_ENDPOINT,
status_code
)
else
vuln_table.state = vulns.STATE.NOT_VULN
end
return vuln_report:make_output(vuln_table)
end
Esempi di utilizzo:```bash
nmap -p 80 --script CVE-2026-22679_Weaver_Ecology_RCE.nse target.com
nmap -p 80,443,8080,8443 --script CVE-2026-22679_Weaver_Ecology_RCE.nse target.com
nmap -p 80 --script CVE-2026-22679_Weaver_Ecology_RCE.nse 10.0.0.0/24
nmap -p 80 --script CVE-2026-22679_Weaver_Ecology_RCE.nse -v target.com
nmap -p 80 --script http-title,http-headers,CVE-2026-22679_Weaver_Ecology_RCE.nse target.com
**Output di esempio:**```
PORT STATE SERVICE
80/tcp open http
| CVE-2026-22679_Weaver_Ecology_RCE:
| VULNERABLE:
| Weaver E-cology Unauthenticated RCE (CVE-2026-22679)
| State: VULNERABLE
| Risk level: CRITICAL
| Debug endpoint: accessible at /papi/esearch/data/devops/dubboApi/debug/method
| Description:
| The dubboApi debug endpoint is exposed without authentication.
| An attacker can send POST requests with crafted parameters to
| achieve remote code execution. Update to build 20260312.
| Discovery Date: 2026-03-12
| Disclosure Date: 2026-03-31
| IDs:
| CVE: CVE-2026-22679
| CWE: CWE-94 (Code Injection)
| References:
|_ https://nvd.nist.gov/vuln/detail/CVE-2026-22679
/papi/esearch/data/devops/dubboApi/debug/methodinterfaceName o methodNameLog di Accesso del Server Web:``` POST /papi/esearch/data/devops/dubboApi/debug/method HTTP/1.1 200 - POST /papi/esearch/data/devops/dubboApi/debug/method HTTP/1.1 405 - GET /papi/esearch/data/devops/dubboApi/debug/method HTTP/1.1 405 -
**Log applicativi:**
- Eccezioni o errori relativi all'invocazione RPC di Dubbo
- Avvisi di parametri non validati nei log del framework RPC
- ClassNotFoundException o errori di invocazione dei metodi
- Tentativi imprevisti di risoluzione delle interfacce
### Indicatori a livello di host
- Processi figlio imprevisti generati dal processo Java di Weaver
- Nuovi account utente creati sul sistema
- Connessioni di rete impreviste dal servizio Weaver
- Modifica dei file di configurazione di Weaver
- Presenza di webshell nelle directory di Weaver
- Scritture di file insolite nelle directory di sistema
- Voci sospette in cronjob o servizi
### Indicatori a livello di file system
- File imprevisti in `/tmp/` o `/var/tmp/`
- File JAR di Weaver o file di configurazione modificati
- Nuovi script shell nelle directory accessibili via web
- Presenza di nomi di file webshell comuni (shell.jsp, cmd.jsp, ecc.)
---
## Rimedio
### Azioni immediate (0-24 ore)
1. **Disabilitare l'accesso di rete all'endpoint di debug**
Aggiungere una regola firewall per bloccare l'accesso all'endpoint vulnerabile: ```
# iptables example
iptables -I INPUT -p tcp --dport 80 -m string --string "/papi/esearch/data/devops/dubboApi" --algo bm -j DROP
# nginx example
location /papi/esearch/data/devops/dubboApi {
return 403;
}
# Apache example
<Location "/papi/esearch/data/devops/dubboApi">
Deny from all
</Location>
Monitorare lo sfruttamento attivo
Limitare l'accesso di rete
Applicare la patch ufficiale
Aggiornare a Weaver E-cology build 20260312 o successiva: ```bash
cp -r /opt/ecology /opt/ecology.backup.20260415
/opt/ecology/bin/upgrade.sh --version 20260312
curl -X POST http://localhost/papi/esearch/data/devops/dubboApi/debug/method
Esaminare i log di accesso
Condurre analisi forense dell'host
Valutazione completa del sistema
Implementare la segmentazione di rete
Hardening
Aggiornare il monitoraggio della sicurezza
Kerem Oruc (@keraattin)
Disclaimer: Queste informazioni sono fornite esclusivamente a scopo educativo e di sicurezza difensiva. L'accesso non autorizzato ai sistemi informatici è illegale. Ottenere sempre la dovuta autorizzazione prima di testare o accedere a sistemi che non si possiedono.
Ultimo aggiornamento: 2026-04-15
| Aspetto | Dettagli |
|---|
| ID CVE | CVE-2026-22679 |
| Punteggio CVSS | 9.3 (Critico) |
| Vettore CVSS | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CWE | CWE-94 (Iniezione di Codice) |
| Fornitore | Weaver (Fanwei) |
| Prodotto | E-cology 10.0 |
| Tipo di Vulnerabilità | Esecuzione Remota di Codice (RCE) non autenticata |
| Endpoint Interessato | /papi/esearch/data/devops/dubboApi/debug/method |
| Vettore di Attacco | Rete / HTTP POST |
| Autenticazione Richiesta | Nessuna |
| Versioni Interessate | Versioni 10.0 precedenti alla build 20260312 |
| Versione Corretta | Build 20260312 (rilasciata il 2026-03-12) |
| Sfruttamento Attivo | Dal 2026-03-31 (Shadowserver Foundation) |
| Metodo di Patch | Rimozione completa dell'endpoint vulnerabile |
| Parametro | Tipo | Descrizione | Esempio |
|---|
interfaceName | String | Nome della classe dell'interfaccia RPC (controllato dall'attaccante) | com.weaver.rpc.InvokeCommand |
methodName | String | Nome del metodo da invocare (controllato dall'attaccante) | executeCommand |
parameters | Array | Parametri del metodo passati direttamente alla logica di esecuzione | ["id"] |
| Area di Impatto | Gravità | Dettagli |
|---|
| Riservatezza | CRITICA | Accesso non autenticato a tutti i dati di sistema, documenti, credenziali utente, contenuti del database |
| Integrità | CRITICA | Capacità di modificare file, documenti, record del database e configurazioni di sistema |
| Disponibilità | CRITICA | Arresto del sistema, esaurimento delle risorse, distruzione dei dati, interruzione dei servizi |
| Ambito | MODIFICATO | L'utente del servizio Weaver esegue tipicamente come root o con account ad alti privilegi; compromissione completa del sistema |
| Versione | Intervallo di Build | Stato | Patch Disponibile |
|---|
| 10.0 | < 20260312 | VULNERABILE | Sì |
| 10.0 | >= 20260312 | CORRETTA | N/D (endpoint rimosso) |
| 9.x e precedenti | Tutte | SCONOSCIUTO | Verificare con il fornitore |