CVE-2026-19188

EUVD-2026-58755
A critical OS command injection vulnerability has been identified in the
 Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the 
Net Check feature accessible via the /setting endpoint. The cmdPing 
Socket.io event fails to properly sanitize user-supplied input before 
passing it to the underlying operating system, allowing an attacker to 
inject and execute arbitrary OS commands with root privileges.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H