Weaver Network Co., Ltd. Vulnerabilities and Affected Products
Vulnerabilities associated with E-cology.
Products
Clear product- E-cology2 vulnerabilities
- E-cology 8.02 vulnerabilities
- E-cology 9.02 vulnerabilities
- E-office1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-50992HIGH | Weaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServletWeaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowService.LoadTemplateProp methods. Attackers can exploit these methods without authentication to retrieve sensitive files including system configuration files and database credentials from the server. Explo… CWE-22Apr 30, 2026 | CVSS8.7v4.0 | EPSS0.705% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22679CRITICAL | Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug EndpointWeaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute arbitrary commands by invoking exposed debug functionality. Attackers can craft POST requests with attacker-controlled interfaceName and methodName parameters to reach command-execution helpers and achieve arbitrary command execution on the system. Exploitation evidence was first ob… CWE-306Apr 7, 2026 | CVSS9.3v4.0 | EPSS21.5% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |