THE advisory, ICSA-26-225-02, issued on August 13, 2026, highlights a critical OS command injection vulnerability in the Haiwell IoT Cloud HMI Gateway, specifically version 3.40.1.12. The vulnerability allows attackers to execute arbitrary OS commands with root privileges via improper input sanitization in the Net Check feature. This poses risks to critical infrastructure sectors such as energy and water systems. Mitigation is available through patch version Scada-v3.50.1.19. The advisory emphasizes minimizing network exposure and implementing robust cyber defense strategies.
Critical command injection bug in Haiwell's IoT Cloud HMI Gateway
CyberSIXT Evidence Panel
Primary Source
github.com
Article by CyberSIXT