Critical flaw gives root on Haiwell industrial gateways

CISA published a run of industrial control system advisories on August 13, and the worst of them carries the maximum possible severity score. A command injection flaw in Haiwell's IoT Cloud HMI Gateway, tracked as CVE-2026-19188, is rated 10 out of 10 on both the CVSS 3.1 and CVSS 4.0 scales, and lets an attacker who can reach the device over the network run operating system commands on it as root, with no credentials required.

The gateway connects Haiwell operator panels and controllers to the vendor's cloud service. CISA lists it as deployed worldwide across the energy, critical manufacturing, and water and wastewater sectors, and puts the vendor's headquarters in China. According to the advisory, the flaw sits in the Net Check feature reached through the /setting endpoint, where the cmdPing Socket.io event hands user supplied input to the operating system without sanitizing it first. Version 3.40.1.12 is affected. Haiwell has fixed it in Scada-v3.50.1.19, available from the vendor's download page, and researcher Fiqram Akmal reported the issue to CISA.

CISA has not said the flaw is being exploited. Reaching it still requires network access to the gateway, which is the whole point of the agency's standing advice for this class of kit: keep control system devices off the public internet, put them behind firewalls, and separate them from the business network. Exposed operator interfaces keep turning up in its casework, from water utilities locked out of internet facing PLCs to fuel terminal controllers shipping with an open root debug port.

What else CISA flagged

Ten more advisories went out the same day, most of them for Siemens products, which Siemens ProductCERT reported to CISA itself. Ordered by severity:

What you should do

Haiwell's gateway is the one to move on first: it needs no credentials, it hands over root, and it sits in front of physical process equipment. After that, the two hardcoded key issues deserve attention out of proportion to their middling scores, because a key shared across every installation is not something a firewall rule fixes and, in the LOGO! case, the update alone is not enough without the matching hardware. Every product named above has a fixed version available, so this is a patching exercise rather than a mitigation one. Where a patch window is weeks away, CISA's usual compensating controls apply: minimize network exposure, keep the devices off the internet, and put remote access behind a VPN that is itself kept current.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions