Critical Vulnerability in Industrial IoT Gateway
CISA has disclosed a maximum-severity vulnerability (CVE-2026-19188, CVSS 10.0) in Haiwell IoT Cloud HMI Gateway version 3.40.1.12. The flaw exists in the Net Check feature's cmdPing Socket.io event, which fails to sanitize user input before passing it to the operating system. This allows attackers to inject and execute arbitrary OS commands with root privileges—the highest level of system access. The gateway is deployed worldwide across energy, critical manufacturing, and water infrastructure sectors.
What This Means for SMBs
Industrial IoT and operational technology devices are increasingly common in manufacturing, facilities management, and infrastructure environments—but they're often overlooked in security audits. A vulnerability this severe in an internet-connected gateway can provide attackers with a direct path to your network, enabling data theft, ransomware deployment, or operational disruption. If your organization uses Haiwell gateways or similar IoT/HMI devices, immediately inventory these assets, segment them from your core network, and apply vendor patches as soon as they're available. This is also a reminder that vendor security matters: evaluate the security posture and patch cadence of any IoT or OT equipment before deployment.
Secure Your Infrastructure
O-Cyrus helps SMBs identify and secure overlooked attack surfaces including IoT, OT, and industrial control systems. Our security assessments include asset discovery, network segmentation planning, and vendor risk evaluation. Contact us to ensure your industrial and IoT devices aren't creating unmanaged risk.
Need a hand with this?
O-Cyrus helps small businesses with websites, DNS, custom apps, and the everyday tech that keeps things running.
Talk to us →