A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway appliance. The vulnerability resides in the Net Check functionality accessible through the /setting endpoint, specifically within the cmdPing Socket.io event. Improper input sanitization allows attackers to inject and execute arbitrary operating system commands with root-level privileges. This flaw, rated CVSS 10.0, enables full system compromise, including data exfiltration, service disruption, or lateral movement within networks. All deployed instances of the Haiwell IoT Cloud HMI Gateway are affected. Attackers could exploit this remotely without authentication, making the risk exceptionally severe. Immediate application of vendor-provided security patches is strongly recommended. In the absence of patches, organizations should implement strict input validation, disable unused features, and monitor for suspicious command execution patterns. This vulnerability underscores the importance of securing IoT gateway interfaces against injection attacks.