CVE-2026-19188Root OS Command Injection in Haiwell IoT Cloud HMI
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.
View on NVDAnalysis
Esta vulnerabilidad de inyección de comandos en el gateway Haiwell IoT Cloud HMI permite a un atacante ejecutar comandos arbitrarios con privilegios de root a través de la red. El fallo ocurre por una falta de sanitización en el evento cmdPing de Socket.io dentro de la interfaz de configuración del dispositivo. Es un riesgo crítico para desarrolladores y operadores de infraestructura de automatización industrial y monitoreo remoto.
Relevant roles
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-78EPSS
No EPSS score yet (CVE may be too fresh).
Technical description
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.