A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway appliance. The vulnerability resides in the Net Check functionality accessible through the /setting endpoint, specifically within the cmdPing Socket.io event. Improper input sanitization allows attackers to inject and execute arbitrary operating system commands with root-level privileges. This flaw, rated CVSS 10.0, enables full system compromise, including data exfiltration, service disruption, or lateral movement within networks. All deployed instances of the Haiwell IoT Cloud HMI Gateway are affected. Attackers could exploit this remotely without authentication, making the risk exceptionally severe. Immediate application of vendor-provided security patches is strongly recommended. In the absence of patches, organizations should implement strict input validation, disable unused features, and monitor for suspicious command execution patterns. This vulnerability underscores the importance of securing IoT gateway interfaces against injection attacks.
CRITICAL
CVSS 10.0
CVE-2026-19188
2026-08-19
Critical OS Command Injection Vulnerability in Haiwell IoT Cloud HMI Gateway (CVE-2026-19188)
A critical OS command injection vulnerability in Haiwell IoT Cloud HMI Gateway allows remote attackers to execute arbitrary commands with root privileges via the Net Check feature. Immediate patching is required to mitigate exploitation risks.