Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-19188Root OS Command Injection in Haiwell IoT Cloud HMI

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.

View on NVD

Analysis

Esta vulnerabilidad de inyección de comandos en el gateway Haiwell IoT Cloud HMI permite a un atacante ejecutar comandos arbitrarios con privilegios de root a través de la red. El fallo ocurre por una falta de sanitización en el evento cmdPing de Socket.io dentro de la interfaz de configuración del dispositivo. Es un riesgo crítico para desarrolladores y operadores de infraestructura de automatización industrial y monitoreo remoto.

Relevant roles

HardwareCyberSecurityBackendJavascriptLinux

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-78

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.

Published: 8/14/2026, 7:17:17 PM
Last modified: 8/14/2026, 7:17:17 PM

References

HomeEventsBlogResourcesCoursesTeam