Haiwell IoT Cloud HMI Gateway

Plan PatchCVSS 10ICS-CERT ICSA-26-225-02Aug 13, 2026
Manufacturing
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A remote code execution vulnerability exists in Haiwell IoT Cloud HMI Gateway that allows an attacker to inject and execute arbitrary OS commands with root privileges. The vulnerability is remotely exploitable without authentication and affects the gateway's command processing functionality.

What this means
What could happen
An attacker could run commands with root-level access on your HMI gateway, potentially allowing them to modify process parameters, stop production systems, or compromise other connected industrial devices on your network.
Who's at risk
Manufacturing facilities using Haiwell IoT Cloud HMI Gateway (especially those relying on it for supervisory control and monitoring of production equipment, PLCs, and other industrial devices). Any organization that has deployed this gateway as an interface between their industrial control systems and remote monitoring or cloud connectivity is affected.
How it could be exploited
An attacker with network access to the gateway can send a crafted command injection payload to the gateway's network interface. The gateway processes this input without proper sanitization, allowing arbitrary OS commands to execute with root privileges, giving the attacker full control of the device and access to connected systems.
Prerequisites
  • Network access to the Haiwell IoT Cloud HMI Gateway
  • No authentication required
remotely exploitableno authentication requiredlow complexityhigh CVSS score (10.0)affects HMI/supervisory systemsroot-level command execution
Exploitability
Some exploitation risk — EPSS score 1.9%
Affected products (1)
ProductAffected VersionsFix Status
Haiwell IoT Cloud HMI Gateway: 3.40.1.123.40.1.12No fix yet
Remediation & Mitigation
0/3
Do now
0/2
WORKAROUNDRestrict network access to the Haiwell gateway to only authorized engineering workstations and control systems using firewall rules and access control lists
HARDENINGIsolate the HMI gateway on a separate network segment or VLAN from untrusted networks and the internet pending patching
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Haiwell IoT Cloud HMI Gateway to firmware version Scada-v3.50.1.19 or later from https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361
API: /api/v1/advisories/66c6da36-05c6-4be3-97c1-8d72bb73a8ad

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.