Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-19188: Haiwell IoT Cloud HMI Gateway allows attackers to run commands

CVE-2026-19188 · published 20 days ago
Summary

An attacker can exploit a weakness in the Haiwell IoT Cloud HMI Gateway, potentially allowing them to access sensitive areas of the system. This could lead to unauthorized changes or data theft. Update the software to the latest version to fix the issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
haiwell haiwell iot cloud hmi gateway 3.40.1.12
Original advisory text
Haiwell IoT Cloud HMI Gateway OS Command Injection
A critical OS command injection vulnerability has been identified in the
Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the
Net Check feature accessible via the /setting endpoint. The cmdPing
Socket.io event fails to properly sanitize user-supplied input before
passing it to the underlying operating system, allowing an attacker to
inject and execute arbitrary OS commands with root privileges.
Severity
10.0 Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
Timeline
Published14 Aug 2026
Updated30 Aug 2026
First seen14 Aug 2026
Sources
CVE-2026-19188 · MITRE
Monitor software like this
Free during beta