CVE-2026-19188

Summary

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.

Affected Software

VendorProductVersion RangeStatus
HaiwellHaiwell IoT Cloud HMI Gateway3.40.1.12affected
HaiwellHaiwell IoT Cloud HMI Gateway3.50.1.19unaffected

Weaknesses

  • CWE-78: CWE-78

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References