Critical OS Command Injection Vulnerability Discovered in Haiwell IoT Cloud HMI Gateway
A critical command injection vulnerability (CVE-2026-19188) has been identified in the Haiwell IoT Cloud HMI Gateway product. The flaw exists in the Net Check feature accessible via the /setting endpoint, where the cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system. Successful exploitation may allow an attacker to inject and execute arbitrary OS commands with root privileges. The vulnerability affects Haiwell IoT Cloud HMI Gateway version 3.40.1.12 and earlier. Haiwell has addressed the issue in patch version Scada-v3.50.1.19. The vulnerability has been reported to CISA by Fiqram Akmal. No known public exploitation has been reported to CISA at the time of publication. The vulnerability is classified as critical with CVSS scores of 3.1 and 4.0. Affected sectors include Energy, Critical Manufacturing, and Water and Wastewater.