CVE-2026-19188Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-14); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-14: 2Mentions · 2026-08-16: 1Mentions · 2026-08-17: 1Technical Details · 2026-08-14: 2Technical Details · 2026-08-16: 1Technical Details · 2026-08-17: 108-1408-1608-17
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-142
Disclosure2
2026-08-161
Disclosure1
2026-08-171
Disclosure1
Full discourse4 posts
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    A critical Haiwell HMI Gateway flaw (CVE-2026-19188) allows remote attackers to execute arbitrary OS commands with root privileges. #Haiwell #CVE202619188 #Vulnerability #CISA https://securityonline.info/haiwell-hmi-gateway-cve-2026-19188/

    Post summary

    Haiwell HMI Gateway flaw (CVE-2026-19188) permits remote attackers to execute arbitrary OS commands with root privileges; the text discloses the vulnerability but provides no PoC, exploit, or patch details.

    00030448
    13.0K followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🏭 CISA ICS advisory issued for CVE-2026-19188 — OS command injection in Haiwell IoT Cloud HMI Gateway via the Net Check feature at /setting. CVSS 10. No auth needed, network exploitable. #cybersecurity #ics #scada #ciso #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-19188?utm_campaign=x https://t.co/5Aamu5Nnkf

    Post summary

    CISA issued an advisory alerting on CVE-2026-19188, an OS command injection flaw in Haiwell IoT Cloud HMI Gateway with CVSS 10, no authentication required, and network exploitable.

    10000139
    877 followersView on X
  • CVETodo@CveTodo
    Disclosure

    A maximum-severity OS command injection vulnerability in the Haiwell IoT Cloud HMI Gateway — tracked as CVE-2026-19188 — allows unauthenticated remote attackers to execute arbitrary... https://cvetodo.com/news/cisa-flags-maximum-severity-command-injection-flaw-in-haiwell-iot-gateway-deployed-across-energy-wat #Haiwell #CommandInjection #CriticalVulnerability #CVE #InfoSec https://t.co/hGguB9QhmI

    Post summary

    CISA highlighted CVE-2026-19188 as a maximum‑severity OS command injection flaw in Haiwell IoT Cloud HMI Gateway, enabling unauthenticated remote execution of arbitrary commands.

    0000060
    19 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-19188 Root OS Command Injection in Haiwell IoT Cloud HMI Gateway via Net Check https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19188

    Post summary

    CVE-2026-19188 is a root OS command injection vulnerability in Haiwell IoT Cloud HMI Gateway, detailed in the brief description, with no PoC, exploit code, patch, or active exploitation reported.

    00000135
    4.1K followersView on X

Explore more