Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-19188: Haiwell IoT Cloud HMI Gateway allows attackers to run commands
CVE-2026-19188 · published 20 days ago
Summary
An attacker can exploit a weakness in the Haiwell IoT Cloud HMI Gateway, potentially allowing them to access sensitive areas of the system. This could lead to unauthorized changes or data theft. Update the software to the latest version to fix the issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| haiwell | haiwell iot cloud hmi gateway | 3.40.1.12 |
Original advisory text
Haiwell IoT Cloud HMI Gateway OS Command Injection
A critical OS command injection vulnerability has been identified in the
Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the
Net Check feature accessible via the /setting endpoint. The cmdPing
Socket.io event fails to properly sanitize user-supplied input before
passing it to the underlying operating system, allowing an attacker to
inject and execute arbitrary OS commands with root privileges.
Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the
Net Check feature accessible via the /setting endpoint. The cmdPing
Socket.io event fails to properly sanitize user-supplied input before
passing it to the underlying operating system, allowing an attacker to
inject and execute arbitrary OS commands with root privileges.
Severity
10.0
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
Timeline
Published14 Aug 2026
Updated30 Aug 2026
First seen14 Aug 2026
Monitor software like this
Free during beta