AllCyberNews

CVE-2026-19188

Haiwell IoT Cloud HMI Gateway OS Command Injection

CVSS 10 critical · Haiwell Haiwell IoT Cloud HMI Gateway · published 2026-08-14

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.

Coverage 1 source

  1. 2026-08-13 CISA Cybersecurity Advisories critical Haiwell IoT Cloud HMI Gateway

    Haiwell IoT Cloud HMI Gateway has a vulnerability allowing OS command injection with root privileges.

Also covered