• Haiwell IoT Cloud HMI Gateway

    From Cisa Advisories@2:263/1 to All on Thu Aug 13 18:03:06 2026
    Haiwell IoT Cloud HMI Gateway

    View CSAF
    Summary
    Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges. The following versions of Haiwell IoT Cloud HMI Gateway are affected:

    Haiwell IoT Cloud HMI Gateway 3.40.1.12 (CVE-2026-19188)





    CVSS
    Vendor
    Equipment
    Vulnerabilities




    v3 10
    Haiwell
    Haiwell IoT Cloud HMI Gateway
    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')




    Background

    Critical Infrastructure Sectors: Energy, Critical Manufacturing, Water and Wastewater
    Countries/Areas Deployed: Worldwide Company Headquarters Location: China


    Vulnerabilities

    Expand All +

    CVE-2026-19188

    A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges View CVE Details

    Affected Products
    Haiwell IoT Cloud HMI Gateway

    Vendor:Haiwell
    Product Version:Haiwell Haiwell IoT Cloud HMI Gateway: 3.40.1.12 Product Status:known_affected


    Remediations
    MitigationHaiwell has addressed the issue in patch version number Scada-v3.50.1.19, which is available for download on their website: https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang
    =en&id=361https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=d odown&lang=en&id=361

    Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    10
    CRITICAL
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H


    4.0
    10
    CRITICAL
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H








    Acknowledgments

    Fiqram Akmal reported this vulnerability to CISA


    Legal Notice and Terms of Use
    This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).

    Recommended Practices
    CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk
    assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices
    on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
    CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation
    Strategies.
    Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
    No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.

    Revision History

    Initial Release Date: 2026-08-13




    Date
    Revision
    Summary




    2026-08-13
    1
    Initial Publication




    Legal Notice and Terms of Use

    https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-02

    2026-08-13 12:00 UTC

    --- BBBS/LiR v4.10 Toy-7
    * Origin: LISTS. from TCOB1 READ ONLY (2:263/1)