{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/haiwell-iot-cloud-hmi-gateway-3.40.1.12/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Haiwell IoT Cloud HMI Gateway (3.40.1.12)"],"_cs_severities":["critical"],"_cs_tags":["ics","rce","cve-2026-19188","critical-infrastructure"],"_cs_type":"advisory","_cs_vendors":["Haiwell"],"content_html":"\u003cp\u003eA critical OS command injection vulnerability (CVE-2026-19188) has been identified in the Haiwell IoT Cloud HMI Gateway, specifically version 3.40.1.12. The vulnerability exists within the 'Net Check' feature accessible via the '/setting' endpoint. An unauthenticated attacker can interact with the 'cmdPing' Socket.io event to pass unsanitized input to the underlying operating system. Because the application runs with root-level privileges, successful exploitation grants the attacker full control over the gateway device. This vulnerability is of particular concern for operators in the energy, critical manufacturing, and water/wastewater sectors where these gateways are deployed to manage industrial control processes.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full system compromise, allowing an attacker to execute arbitrary OS commands as the root user. Given the role of HMI gateways in critical infrastructure, this could lead to unauthorized control of industrial processes, data exfiltration, or complete service disruption. The CVSS score of 10.0 reflects the high risk to both confidentiality, integrity, and availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Haiwell IoT Cloud HMI Gateway to patch version Scada-v3.50.1.19 immediately.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the '/setting' endpoint and the Socket.io interface to authorized internal management IP addresses only.\u003c/li\u003e\n\u003cli\u003eIsolate all industrial HMI gateways from the public internet using firewalls and VPNs to prevent remote exploitation of this unauthenticated vector.\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for unexpected POST or WebSocket activity targeting the '/setting' endpoint, particularly those containing shell metacharacters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T16:53:17Z","date_published":"2026-08-13T16:53:17Z","id":"https://feed.craftedsignal.io/briefs/2026-08-haiwell-hmi-rce/","summary":"An unauthenticated OS command injection vulnerability in the Haiwell IoT Cloud HMI Gateway allows attackers to achieve arbitrary command execution with root privileges via the Net Check feature.","title":"Critical OS Command Injection in Haiwell IoT Cloud HMI Gateway","url":"https://feed.craftedsignal.io/briefs/2026-08-haiwell-hmi-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Haiwell IoT Cloud HMI Gateway (3.40.1.12)","version":"https://jsonfeed.org/version/1.1"}