A critical OS command injection vulnerability has been identified in the
Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the
Net Check feature accessible via the /setting endpoint. The cmdPing
Socket.io event fails to properly sanitize user-supplied input before
passing it to the underlying operating system, allowing an attacker to
inject and execute arbitrary OS commands with root privileges.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges. | |
| Title | Haiwell IoT Cloud HMI Gateway OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-14T18:52:46.447Z
Reserved: 2026-08-06T19:51:14.688Z
Link: CVE-2026-19188
Updated: 2026-08-14T18:52:42.909Z
Status : Received
Published: 2026-08-14T19:17:17.480
Modified: 2026-08-14T19:17:17.480
Link: CVE-2026-19188
No data.
OpenCVE Enrichment
Updated: 2026-08-14T19:30:04Z