CVE-2026-19188Inyección de comandos root en Haiwell IoT Cloud HMI
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.
Ver en NVDAnálisis
Esta vulnerabilidad de inyección de comandos en el gateway Haiwell IoT Cloud HMI permite a un atacante ejecutar comandos arbitrarios con privilegios de root a través de la red. El fallo ocurre por una falta de sanitización en el evento cmdPing de Socket.io dentro de la interfaz de configuración del dispositivo. Es un riesgo crítico para desarrolladores y operadores de infraestructura de automatización industrial y monitoreo remoto.
Roles relevantes
Severidad
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-78EPSS
Sin puntaje EPSS aún (CVE muy reciente).
Descripción técnica
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.