AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19188

CRITICAL · CVSS 10 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A critical OS command injection vulnerability exists in the Net Check feature of the Haiwell IoT Cloud HMI Gateway, specifically through the /setting endpoint. This flaw allows attackers to inject and execute arbitrary OS commands with root privileges, potentially compromising the entire system. Organizations using this product should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19188
Severity
CRITICAL
CVSS
10
EPSS
N/A

Original NVD Description

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.