Schneider Electric NetBotz 5 750/755 Multiple Vulnerabilities (OS Command Injection & SQL Injection)
First seen Sep 20, 2026 · Updated Sep 20, 2026 · CVSS 6.4
Schneider Electric's NetBotz 5 750/755 environmental and security monitoring devices contain two medium-severity vulnerabilities: an OS command injection flaw triggered via a maliciously modified backup restore, and a Hibernate SQL injection flaw exploitable through the web UI or web-service interface. Successful exploitation could allow arbitrary Linux command execution, device manipulation, and unauthorized data access on the local network. Schneider Electric has released version 5.6.0 to remediate both issues.
Technical Analysis
CVE-2026-13336 (CVSS 3.1: 6.4, AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H) is a CWE-78 OS command injection triggered when a maliciously crafted backup file is restored on the device, enabling execution of arbitrary Linux OS commands. CVE-2026-13337 (CVSS 3.1: 4.6, AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N) is a CWE-564 Hibernate SQL injection allowing an authenticated attacker to inject malicious HQL queries via the web-service interface or web-UI, risking unauthorized data disclosure. Both require adjacent network access and some level of privilege, limiting remote mass exploitability, but successful attacks could enable full device compromise, data manipulation, and pivoting within OT/IT environments. These are physical/environmental monitoring appliances (temperature, humidity, leak, smoke, video) rather than AI agent infrastructure, so there is no direct or plausible impact to AI agent systems, LLM tool use, or RAG pipelines.
Affected Systems
NetBotz 5 750 versions 5.5.2 and prior; NetBotz 5 755 versions 5.5.2 and prior. Fixed in version 5.6.0.
Indicators of Compromise
- Not applicable - this is a vendor vulnerability disclosure with no known active exploitation or associated indicators of compromise reported.
Remediation Steps
- 1
Upgrade to NetBotz 5.6.0
Download and install version 5.6.0 from Schneider Electric's official software/firmware portal, which remediates both CVE-2026-13336 and CVE-2026-13337. The device will automatically restart upon installation; verify the update via the 'About NetBotz' GUI option.
- 2
Restrict network exposure
Ensure NetBotz devices are isolated from business networks and are not accessible from the internet; place them behind firewalls on segmented control/monitoring networks.
- 3
Secure backup handling
Only restore backups from trusted, verified sources to prevent exploitation of the OS command injection vulnerability via maliciously modified backup files.
- 4
Enforce strong access controls
Limit and audit privileged access to the NetBotz web-UI and web-service interface to reduce risk of SQL injection exploitation by authenticated malicious users.
- 5
Use secure remote access
If remote access is required, use up-to-date VPN solutions and follow Schneider Electric's recommended cybersecurity best practices document.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.