A critical OS command injection vulnerability has been identified in the
Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the
Net Check feature accessible via the /setting endpoint. The cmdPing
Socket.io event fails to properly sanitize user-supplied input before
passing it to the underlying operating system, allowing an attacker to
inject and execute arbitrary OS commands with root privileges.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-14 19:17
Updated : 2026-09-08 19:30
NVD link : CVE-2026-19188
Mitre link : CVE-2026-19188
CVE.ORG link : CVE-2026-19188
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
