Cyber Resilience
← All news
Confirmed

Haiwell IoT Cloud HMI Gateway

Our takeCISA reports active exploitation of CVE-2026-19188: unauthenticated OS command injection letting attackers run arbitrary commands as root on Haiwell IoT Cloud HMI Gateway 3.40.1.12. Patch immediately if you run this gear.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation of an unauthenticated OS command injection (CVE-2026-19188) in Haiwell IoT Cloud HMI Gateway 3.40.1.12 that reaches root. Patch immediately if you self-host this version; isolate or air-gap the device until you can.
What this means for you — Lean IT orgs:If you use a Haiwell IoT Cloud HMI Gateway on version 3.40.1.12, update it right away. This flaw lets attackers run commands as root with no login required.
What this means for you — MSP:CISA reports active exploitation of CVE-2026-19188 (root-level OS command injection) in Haiwell IoT Cloud HMI Gateway 3.40.1.12. Check client environments for this exact version, patch or isolate immediately, and treat any internet-facing instance as compromised until proven otherwise.
What this means for you — Researcher:CISA reports active exploitation of CVE-2026-19188 in Haiwell IoT Cloud HMI Gateway 3.40.1.12: unauthenticated OS command injection reaching root.