Skip to content
Threat Feed
critical advisory

Critical OS Command Injection in Haiwell IoT Cloud HMI Gateway

An unauthenticated OS command injection vulnerability in the Haiwell IoT Cloud HMI Gateway allows attackers to achieve arbitrary command execution with root privileges via the Net Check feature.

A critical OS command injection vulnerability (CVE-2026-19188) has been identified in the Haiwell IoT Cloud HMI Gateway, specifically version 3.40.1.12. The vulnerability exists within the 'Net Check' feature accessible via the '/setting' endpoint. An unauthenticated attacker can interact with the 'cmdPing' Socket.io event to pass unsanitized input to the underlying operating system. Because the application runs with root-level privileges, successful exploitation grants the attacker full control over the gateway device. This vulnerability is of particular concern for operators in the energy, critical manufacturing, and water/wastewater sectors where these gateways are deployed to manage industrial control processes.

Impact

Successful exploitation of this vulnerability results in full system compromise, allowing an attacker to execute arbitrary OS commands as the root user. Given the role of HMI gateways in critical infrastructure, this could lead to unauthorized control of industrial processes, data exfiltration, or complete service disruption. The CVSS score of 10.0 reflects the high risk to both confidentiality, integrity, and availability.

Recommendation

  • Upgrade the Haiwell IoT Cloud HMI Gateway to patch version Scada-v3.50.1.19 immediately.
  • Restrict network access to the '/setting' endpoint and the Socket.io interface to authorized internal management IP addresses only.
  • Isolate all industrial HMI gateways from the public internet using firewalls and VPNs to prevent remote exploitation of this unauthenticated vector.
  • Monitor webserver logs for unexpected POST or WebSocket activity targeting the '/setting' endpoint, particularly those containing shell metacharacters.

Immediate actions

Inventory all Haiwell IoT Cloud HMI Gateway devices and verify firmware version.

IT Operations 24h

Deploy WAF or network filtering rules to block malicious payloads targeting /setting.

SOC 24h

Mitigations

Patch devices to Scada-v3.50.1.19.

immediate IT Operations

CVE-2026-19188

Detection coverage 1

Detects CVE-2026-19188 Exploitation - Command Injection via Socket.io

critical

Detects potential exploitation attempts against the Haiwell HMI Gateway Net Check feature by monitoring for shell metacharacters in traffic targeting the /setting endpoint.

sigma tactics: execution, initial_access techniques: T1203 sources: webserver

Detection queries are available on the platform. Get full rules →