CVE-2026-19188 PUBLISHED

Haiwell IoT Cloud HMI Gateway OS Command Injection

Assigner: icscert
Reserved: 06.08.2026 Published: 14.08.2026 Updated: 14.08.2026

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 10

Product Status

Vendor Haiwell
Product Haiwell IoT Cloud HMI Gateway
Versions Default: unaffected
  • Version 3.40.1.12 is affected
  • Version 3.50.1.19 is unaffected

Solutions

Haiwell has addressed the issue in patch version number Scada-v3.50.1.19, which is available for download on their website:  https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361

Credits

  • Fiqram Akmal reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-78 CWE