A vulnerability identified as very critical has been detected in Haiwell IoT Cloud HMI Gateway up to 3.40.1.12. The affected element is the function cmdPing of the file /setting of the component Net Check. The manipulation leads to os command injection.

This vulnerability is uniquely identified as CVE-2026-19188. The attack is possible to be carried out remotely. No exploit exists.

You should upgrade the affected component.