Description
A critical OS command injection vulnerability has been identified in the
Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the
Net Check feature accessible via the /setting endpoint. The cmdPing
Socket.io event fails to properly sanitize user-supplied input before
passing it to the underlying operating system, allowing an attacker to
inject and execute arbitrary OS commands with root privileges.
Published: 2026-08-14
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A critical operating‑system command injection flaw exists in the Net Check feature of the Haiwell IoT Cloud HMI Gateway, accessible via the /setting endpoint. The cmdPing Socket.io event does not sanitize user input before passing it to the underlying OS, enabling an attacker to inject and run arbitrary commands with root privileges. This vulnerability is classified as CWE‑78 (OS Command Injection).

Affected Systems

The vulnerability affects devices running the Haiwell IoT Cloud HMI Gateway product. No specific firmware or software versions are listed in the CVE data; however, the vendor recommends applying the patch in patch version Scada‑v3.50.1.19 to remediate the issue.

Risk and Exploitability

The CVSS score is 10, indicating a high‑severity flaw. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation likely requires network access to the device and the ability to trigger the cmdPing event against the /setting endpoint. Once accessed, an attacker could run arbitrary commands with root privileges, granting complete control over the device. Given the lack of publicly known exploits and the critical severity, the risk is high if the device is exposed to untrusted networks.

Generated by OpenCVE AI on August 14, 2026 at 19:21 UTC.

Remediation

Vendor Solution

Haiwell has addressed the issue in patch version number Scada-v3.50.1.19, which is available for download on their website:  https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361


OpenCVE Recommended Actions

  • Apply the Haiwell patch released in Scada‑v3.50.1.19 via the vendor website
  • Restrict network access to the /setting endpoint, allowing only trusted IP addresses or internal networks
  • Remove or disable the Net Check feature if it is not required in the environment

Generated by OpenCVE AI on August 14, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.
Title Haiwell IoT Cloud HMI Gateway OS Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-14T18:52:46.447Z

Reserved: 2026-08-06T19:51:14.688Z

Link: CVE-2026-19188

cve-icon Vulnrichment

Updated: 2026-08-14T18:52:42.909Z

cve-icon NVD

Status : Received

Published: 2026-08-14T19:17:17.480

Modified: 2026-08-14T19:17:17.480

Link: CVE-2026-19188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T19:30:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')