Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xjrj-4jhg-7qmh

Опубликовано: 14 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 10

Описание

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.

EPSS

Процентиль: 78%
0.0189
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 10
nvd
5 дней назад

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.

EPSS

Процентиль: 78%
0.0189
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-78