← Back to Feed
Haiwell IoT Cloud HMI Gateway
CVE-2026-19188
August 13, 2026 · CISA (US-CERT) · Severity: CRITICAL
Haiwell IoT Cloud HMI Gateway version 3.40.1.12 is vulnerable to OS command injection in the Net Check feature accessed through /setting. The cmdPing Socket.io event passes unsanitized input to the OS, allowing remote attackers to execute commands as root. The vendor released patch Scada-v3.50.1.19 to remediate the issue.
Key Takeaways
- Haiwell IoT Cloud HMI Gateway 3.40.1.12 exposes an OS command injection in the /setting endpoint.
- The cmdPing Socket.io event lacks input sanitization, letting attackers execute arbitrary OS commands with root privileges.
- Haiwell patched this critical CVE-2026-19188 in Scada-v3.50.1.19; apply the update immediately.