TL;DR
A critical Haiwell HMI Gateway flaw threatens industrial control systems worldwide. Specifically, this vulnerability allows unauthenticated attackers to execute commands directly on the host device. Vendors have quickly released a patch to secure affected units.
- CVE: CVE-2026-19188
- CVSS: 10.0 (Critical · CVSSv3)
- Product: Haiwell IoT Cloud HMI Gateway
- Affected: 3.40.1.12
- Impact: Haiwell IoT Cloud HMI Gateway OS Command Injection
- Status: No confirmed exploitation yet
- Patched in: 3.50.1.19
- EPSS: 1.9% (30-day)
- Action: Update to 3.50.1.19 now
Why It Matters
The flaw earned a maximum CVSS score of 10.0. Therefore, it poses an extreme risk to connected infrastructure. Facilities across the Energy, Critical Manufacturing, and Water and Wastewater sectors actively use these devices. These installations often manage highly sensitive physical processes. Consequently, a successful attack could severely disrupt vital global services. According to CISA, “Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges.”
How the Attack Works
The vulnerability exists within the Net Check feature of the device. Users normally access this diagnostic tool via the /setting endpoint. However, the internal cmdPing Socket.io event fails to properly sanitize user-supplied input. Because of this oversight, the application blindly passes malicious input directly to the operating system. As a result, hackers can easily append and inject raw commands. The system then executes these commands natively.
Affected Versions
This vulnerability impacts Haiwell IoT Cloud HMI Gateway version 3.40.1.12. Currently, researchers have not observed active attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Regardless, administrators must act quickly.
Patch and Mitigation Steps
Haiwell has released a firmware update to resolve the problem. Users should immediately download patch version Scada-v3.50.1.19 from the official vendor website. In the meantime, defenders must minimize network exposure for all control system devices. Keep these gateways completely disconnected from the public internet. Furthermore, locate control system networks securely behind strong firewalls. When remote access remains strictly required, use verified virtual private networks. However, remember that VPNs also require regular patching to remain secure.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.