Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the
Net Check feature accessible via the /setting endpoint. The cmdPing
Socket.io event fails to properly sanitize user-supplied input before
passing it to the underlying operating system, allowing an attacker to
inject and execute arbitrary OS commands with root privileges.
Project Subscriptions
No data.
No advisories yet.
Solution
Haiwell has addressed the issue in patch version number Scada-v3.50.1.19, which is available for download on their website: https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361
Workaround
No workaround given by the vendor.
Fri, 14 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges. | |
| Title | Haiwell IoT Cloud HMI Gateway OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-14T18:52:46.447Z
Reserved: 2026-08-06T19:51:14.688Z
Link: CVE-2026-19188
No data.
Status : Received
Published: 2026-08-14T19:17:17.480
Modified: 2026-08-14T19:17:17.480
Link: CVE-2026-19188
No data.
OpenCVE Enrichment
Updated: 2026-08-14T19:30:04Z