Cyber Resilience
← All news
Confirmed

Haiwell IoT Cloud HMI Gateway

Our takeCISA reports active exploitation of CVE-2026-19188: unauthenticated OS command injection reaching root on Haiwell IoT Cloud HMI Gateway 3.40.1.12. Patch immediately if you run these devices.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation of CVE-2026-19188, an unauthenticated OS command injection in Haiwell IoT Cloud HMI Gateway 3.40.1.12 that reaches root. Patch immediately if you self-host this device.
What this means for you — Lean IT orgs:If you use a Haiwell IoT Cloud HMI Gateway on your network, update it to a fixed version right away. Most small teams without this specific hardware can ignore this one.
What this means for you — MSP:Check client environments for any Haiwell IoT Cloud HMI Gateway 3.40.1.12 instances and apply the vendor update; this is an actively exploited root-level command injection per CISA.
What this means for you — Researcher:CISA added CVE-2026-19188 (root-level unauthenticated OS command injection) in Haiwell IoT Cloud HMI Gateway 3.40.1.12 to its Known Exploited Vulnerabilities catalog.