A critical OS command injection vulnerability has been identified in the
Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the
Net Check feature accessible via the /setting endpoint. The cmdPing
Socket.io event fails to properly sanitize user-supplied input before
passing it to the underlying operating system, allowing an attacker to
inject and execute arbitrary OS commands with root privileges.
Haiwell has addressed the issue in patch version number
Scada-v3.50.1.19, which is available for download on their website:
https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361