As cited
Copy frozen at (site build).
vulnerabilities
Haiwell IoT Cloud HMI Gateway
A critical OS command injection vulnerability (CVE-2026-19188, CVSS 10.0) has been identified in Haiwell IoT Cloud HMI Gateway version 3.40.1.12, affecting the Net Check feature's cmdPing Socket.io event. The flaw allows unauthenticated remote attackers to execute arbitrary commands with root privileges by supplying unsanitized input to the /setting endpoint. Haiwell has released patch version 3.50.1.19 to address the issue.
Why it matters: Energy, critical manufacturing, and water and wastewater organizations worldwide using this gateway must apply the patch immediately, as the vulnerability is network-accessible, requires no authentication, and grants root-level command execution.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Haiwell IoT Cloud HMI Gateway
A critical OS command injection vulnerability (CVE-2026-19188, CVSS 10.0) has been identified in Haiwell IoT Cloud HMI Gateway version 3.40.1.12, affecting the Net Check feature's cmdPing Socket.io event. The flaw allows unauthenticated remote attackers to execute arbitrary commands with root privileges by supplying unsanitized input to the /setting endpoint. Haiwell has released patch version 3.50.1.19 to address the issue.
Why it matters: Energy, critical manufacturing, and water and wastewater organizations worldwide using this gateway must apply the patch immediately, as the vulnerability is network-accessible, requires no authentication, and grants root-level command execution.
- Source published
- First seen by Cybersecurity Tracker