CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Haiwell IoT Cloud HMI Gateway

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4397

As cited

Copy frozen at (site build).

vulnerabilities

Haiwell IoT Cloud HMI Gateway

A critical OS command injection vulnerability (CVE-2026-19188, CVSS 10.0) has been identified in Haiwell IoT Cloud HMI Gateway version 3.40.1.12, affecting the Net Check feature's cmdPing Socket.io event. The flaw allows unauthenticated remote attackers to execute arbitrary commands with root privileges by supplying unsanitized input to the /setting endpoint. Haiwell has released patch version 3.50.1.19 to address the issue.

Why it matters: Energy, critical manufacturing, and water and wastewater organizations worldwide using this gateway must apply the patch immediately, as the vulnerability is network-accessible, requires no authentication, and grants root-level command execution.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Haiwell IoT Cloud HMI Gateway

A critical OS command injection vulnerability (CVE-2026-19188, CVSS 10.0) has been identified in Haiwell IoT Cloud HMI Gateway version 3.40.1.12, affecting the Net Check feature's cmdPing Socket.io event. The flaw allows unauthenticated remote attackers to execute arbitrary commands with root privileges by supplying unsanitized input to the /setting endpoint. Haiwell has released patch version 3.50.1.19 to address the issue.

Why it matters: Energy, critical manufacturing, and water and wastewater organizations worldwide using this gateway must apply the patch immediately, as the vulnerability is network-accessible, requires no authentication, and grants root-level command execution.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary