CVE-2026-19188: Haiwell IoT Cloud HMI Gateway
Critical severity, CVSS 10.0. EPSS: 2.9% chance of exploitation in the next 30 days.
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.
Affected products
- Haiwell Haiwell IoT Cloud HMI Gateway: version 3.40.1.12 only
Published 2026-08-14. Last modified 2026-09-08.