Executive brief
The Haiwell IoT Cloud HMI Gateway is a control and monitoring device used to manage industrial processes and facilities. A critical flaw in its Net Check feature allows attackers to inject and execute arbitrary system commands with root-level privileges, potentially giving them complete control over the device and any connected systems.
Technical details
The vulnerability is an OS command injection flaw in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system shell. An unauthenticated network attacker can exploit this by sending a crafted request containing shell metacharacters to execute arbitrary commands with root privileges. The attack requires network reachability to the affected device but no authentication or user interaction.
Affected products
- Haiwell IoT Cloud HMI Gateway
Timeline
- 2026-08-14: disclosed