CVE-2026-19188
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.93%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.
- CVSS 4.0
- 10.0 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 1.93% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Source
- ics-cert@hq.dhs.gov
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.