<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Haiwell - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/haiwell/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 13 Aug 2026 16:53:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/haiwell/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical OS Command Injection in Haiwell IoT Cloud HMI Gateway</title><link>https://feed.craftedsignal.io/briefs/2026-08-haiwell-hmi-rce/</link><pubDate>Thu, 13 Aug 2026 16:53:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-haiwell-hmi-rce/</guid><description>An unauthenticated OS command injection vulnerability in the Haiwell IoT Cloud HMI Gateway allows attackers to achieve arbitrary command execution with root privileges via the Net Check feature.</description><content:encoded><![CDATA[<p>A critical OS command injection vulnerability (CVE-2026-19188) has been identified in the Haiwell IoT Cloud HMI Gateway, specifically version 3.40.1.12. The vulnerability exists within the 'Net Check' feature accessible via the '/setting' endpoint. An unauthenticated attacker can interact with the 'cmdPing' Socket.io event to pass unsanitized input to the underlying operating system. Because the application runs with root-level privileges, successful exploitation grants the attacker full control over the gateway device. This vulnerability is of particular concern for operators in the energy, critical manufacturing, and water/wastewater sectors where these gateways are deployed to manage industrial control processes.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in full system compromise, allowing an attacker to execute arbitrary OS commands as the root user. Given the role of HMI gateways in critical infrastructure, this could lead to unauthorized control of industrial processes, data exfiltration, or complete service disruption. The CVSS score of 10.0 reflects the high risk to both confidentiality, integrity, and availability.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the Haiwell IoT Cloud HMI Gateway to patch version Scada-v3.50.1.19 immediately.</li>
<li>Restrict network access to the '/setting' endpoint and the Socket.io interface to authorized internal management IP addresses only.</li>
<li>Isolate all industrial HMI gateways from the public internet using firewalls and VPNs to prevent remote exploitation of this unauthenticated vector.</li>
<li>Monitor webserver logs for unexpected POST or WebSocket activity targeting the '/setting' endpoint, particularly those containing shell metacharacters.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>ics</category><category>rce</category><category>cve-2026-19188</category><category>critical-infrastructure</category></item></channel></rss>