Haiwell IoT Cloud HMI Gateway
Summary
A critical OS command injection vulnerability, CVE-2026-19188, has been identified in the Haiwell IoT Cloud HMI Gateway product. Successful exploitation could allow an attacker to execute arbitrary OS commands with root privileges. Haiwell has released a patch, version Scada-v3.50.1.19, to address the vulnerability.
IFF Assessment
This vulnerability allows for root privilege escalation and arbitrary command execution, representing a significant risk to defenders.
Severity
Defender Context
Defenders should prioritize patching the Haiwell IoT Cloud HMI Gateway to version Scada-v3.50.1.19 to mitigate the risk of remote code execution and root privilege escalation. This vulnerability impacts critical infrastructure sectors like Energy, Critical Manufacturing, and Water and Wastewater, highlighting the importance of timely security updates for Industrial Control Systems (ICS).