Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-19188

Опубликовано: 14 авг. 2026
Источник: nvd
CVSS3: 10
EPSS Низкий

Описание

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.

EPSS

Процентиль: 78%
0.0189
Низкий

10 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 10
github
4 дня назад

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges.

EPSS

Процентиль: 78%
0.0189
Низкий

10 Critical

CVSS3

Дефекты

CWE-78