Horizon Alert
Summary of the vulnerability and why it matters
A critical security flaw has been found in Haiwell's IoT Cloud HMI Gateway, specifically within its Net Check feature. This vulnerability allows unauthorized access and execution of system commands with the highest level of privilege, posing a significant risk to the integrity and control of connected systems.
- Unauthenticated attackers can run any command on the gateway.
- It impacts industrial control and IoT systems accessed remotely.
- Confirming relevance and exposure is the primary leadership concern.
Attack Path
How an attacker could exploit the issue
An attacker could leverage this vulnerability by sending specially crafted network requests to the Haiwell IoT Cloud HMI Gateway. The Net Check feature, accessible through the /setting endpoint, processes user input via the cmdPing Socket.io event without adequate validation. This allows an attacker to inject operating system commands, which are then executed with root privileges.
- Network access required
- Net Check feature input
- Arbitrary code execution
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an attacker to execute arbitrary operating system commands with root privileges on the Haiwell IoT Cloud HMI Gateway. This risk is present when the "Net Check" feature, accessed via the `/setting` endpoint, is exposed to the network and the `cmdPing` event fails to validate user input.
- Affected system: Haiwell IoT Cloud HMI Gateway.
- Exposure: Network-accessible "Net Check" feature.
- Consequence: Arbitrary command execution with root privileges.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Haiwell IoT Cloud HMI Gateway's "Net Check" feature is susceptible to OS command injection, allowing unauthenticated attackers to execute arbitrary commands with root privileges. This critical vulnerability necessitates immediate attention from teams responsible for the security and operation of these gateways. The first practical step is to identify all instances of the affected HMI Gateway, determine their network exposure and business criticality, and locate the designated owner for remediation planning.
- Ownership: Infrastructure or IoT platform teams.
- Verify: Gateway reachability and criticality.
- Action: Plan coordinated remediation.