PatchSiren

Haiwell CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Haiwell CVE published 2026-08-14

CVE-2026-19188

A critical OS command injection vulnerability exists in the Haiwell IoT Cloud HMI Gateway product, specifically in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.