← Back to Feed

Haiwell IoT Cloud HMI Gateway

CVE-2026-19188

August 13, 2026 · CISA (US-CERT) · Severity: CRITICAL

Haiwell IoT Cloud HMI Gateway version 3.40.1.12 is vulnerable to OS command injection in the Net Check feature accessed through /setting. The cmdPing Socket.io event passes unsanitized input to the OS, allowing remote attackers to execute commands as root. The vendor released patch Scada-v3.50.1.19 to remediate the issue.

Key Takeaways

  • Haiwell IoT Cloud HMI Gateway 3.40.1.12 exposes an OS command injection in the /setting endpoint.
  • The cmdPing Socket.io event lacks input sanitization, letting attackers execute arbitrary OS commands with root privileges.
  • Haiwell patched this critical CVE-2026-19188 in Scada-v3.50.1.19; apply the update immediately.
☕ Buy a Coffee