Haiwell IoT Cloud HMI Gateway

Summary

A critical OS command injection vulnerability, CVE-2026-19188, has been identified in the Haiwell IoT Cloud HMI Gateway product. Successful exploitation could allow an attacker to execute arbitrary OS commands with root privileges. Haiwell has released a patch, version Scada-v3.50.1.19, to address the vulnerability.

IFF Assessment

FOE

This vulnerability allows for root privilege escalation and arbitrary command execution, representing a significant risk to defenders.

Severity

10.0 Critical

Defender Context

Defenders should prioritize patching the Haiwell IoT Cloud HMI Gateway to version Scada-v3.50.1.19 to mitigate the risk of remote code execution and root privilege escalation. This vulnerability impacts critical infrastructure sectors like Energy, Critical Manufacturing, and Water and Wastewater, highlighting the importance of timely security updates for Industrial Control Systems (ICS).

Read Full Story →