Critical OS Command Injection Vulnerability Found in Haiwell IoT Cloud HMI Gateway
CISA has issued an advisory for a critical OS command injection vulnerability (CVE-2026-19188) in Haiwell IoT Cloud HMI Gateway, allowing attackers to execute arbitrary commands with root privileges.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory detailing a severe vulnerability within the Haiwell IoT Cloud HMI Gateway. Identified as CVE-2026-19188, the flaw is an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary operating system commands with the highest level of privilege on affected devices.
The vulnerability resides within the "Net Check" feature, accessible via the /setting endpoint of the gateway. Specifically, the cmdPing Socket.io event fails to adequately sanitize user-supplied input. This oversight permits an attacker to inject malicious commands that are then passed directly to the underlying operating system, effectively granting them root-level control over the compromised gateway.
The affected product is the Haiwell IoT Cloud HMI Gateway, with versions prior to 3.40.1.12 being susceptible. The CVSS v3.1 score for this vulnerability is a perfect 10.0 (CRITICAL), indicating a severe risk. The CVSS v4.0 score is also 10.0 CRITICAL. This high severity rating is due to the ease of exploitation, the lack of authentication requirements, and the potential for complete system compromise.
Successful exploitation of this vulnerability could have significant consequences for organizations relying on these gateways, particularly in critical infrastructure sectors such as Energy, Critical Manufacturing, and Water and Wastewater. Attackers could potentially disrupt operations, steal sensitive data, or use the compromised gateway as a pivot point into broader industrial control system (ICS) networks.
Haiwell, the vendor, has acknowledged the vulnerability and released a patch to address the issue. Version Scada-v3.50.1.19 is now available for download from the company's official website. CISA strongly recommends that users of the Haiwell IoT Cloud HMI Gateway upgrade to the patched version as soon as possible to mitigate the risk of exploitation.
In addition to patching, CISA advises implementing broader defensive measures. These include minimizing network exposure for all control system devices, ensuring they are not directly accessible from the internet, and locating them behind firewalls. When remote access is necessary, the use of secure methods like Virtual Private Networks (VPNs) is recommended, with the caveat that VPNs themselves must be kept up-to-date and secured.
While no public exploitation of this specific vulnerability has been reported to CISA at this time, the critical nature of the flaw and its potential impact on industrial environments warrant immediate attention. Organizations should conduct thorough impact and risk assessments before deploying any defensive measures and report any suspected malicious activity to CISA.
The vulnerability, categorized under CWE-78 (Improper Neutralization of Special Elements used in an OS Command), highlights the ongoing challenges in securing IoT devices within industrial settings. The global deployment of these gateways, with the company headquartered in China, underscores the need for continuous vigilance and prompt patching across diverse operational technology (OT) environments.