Our takeCISA reports active exploitation of CVE-2026-19188: unauthenticated OS command injection letting attackers run arbitrary commands as root on Haiwell IoT Cloud HMI Gateway 3.40.1.12. Patch immediately if you run this gear.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:CISA reports active exploitation of an unauthenticated OS command injection (CVE-2026-19188) in Haiwell IoT Cloud HMI Gateway 3.40.1.12 that reaches root. Patch immediately if you self-host this version; isolate or air-gap the device until you can.
What this means for you — Lean IT orgs:If you use a Haiwell IoT Cloud HMI Gateway on version 3.40.1.12, update it right away. This flaw lets attackers run commands as root with no login required.
What this means for you — MSP:CISA reports active exploitation of CVE-2026-19188 (root-level OS command injection) in Haiwell IoT Cloud HMI Gateway 3.40.1.12. Check client environments for this exact version, patch or isolate immediately, and treat any internet-facing instance as compromised until proven otherwise.
What this means for you — Researcher:CISA reports active exploitation of CVE-2026-19188 in Haiwell IoT Cloud HMI Gateway 3.40.1.12: unauthenticated OS command injection reaching root.