Impact
A critical operating‑system command injection flaw exists in the Net Check feature of the Haiwell IoT Cloud HMI Gateway, accessible via the /setting endpoint. The cmdPing Socket.io event does not sanitize user input before passing it to the underlying OS, enabling an attacker to inject and run arbitrary commands with root privileges. This vulnerability is classified as CWE‑78 (OS Command Injection).
Affected Systems
The vulnerability affects devices running the Haiwell IoT Cloud HMI Gateway product. No specific firmware or software versions are listed in the CVE data; however, the vendor recommends applying the patch in patch version Scada‑v3.50.1.19 to remediate the issue.
Risk and Exploitability
The CVSS score is 10, indicating a high‑severity flaw. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation likely requires network access to the device and the ability to trigger the cmdPing event against the /setting endpoint. Once accessed, an attacker could run arbitrary commands with root privileges, granting complete control over the device. Given the lack of publicly known exploits and the critical severity, the risk is high if the device is exposed to untrusted networks.
OpenCVE Enrichment