CISA

Haiwell IoT Cloud HMI Gateway

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges.

The following versions of Haiwell IoT Cloud HMI Gateway are affected:

Haiwell IoT Cloud HMI Gateway 3.40.1.12 (CVE-2026-19188)

Vendor

Equipment

Haiwell

Haiwell IoT Cloud HMI Gateway

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Critical Infrastructure Sectors: Energy, Critical Manufacturing, Water and Wastewater

Countries/Areas Deployed: Worldwide

Company Headquarters Location: China

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating...