Junglewise Threat Intelligence

CVE-2026-13337: Schneider Electric NetBotz 5 750/755 OS command injection and SQL injection

CVE-2026-13337 · Severity: high · CVSS 6.4 · Published 2026-09-17

Executive brief

Schneider Electric NetBotz 5 750/755 is a security and environmental monitoring system used to track temperature, humidity, leaks, smoke, and video in data centers and facilities. The devices contain two critical vulnerabilities that allow attackers with local network access to execute arbitrary system commands or inject malicious database queries, potentially leading to unauthorized control of the monitoring system and access to sensitive environmental and security data.

Technical details

CVE-2026-13336 is an OS command injection vulnerability (CWE-78) that arises when a maliciously modified system backup is restored to the NetBotz device, allowing execution of arbitrary Linux operating system commands. CVE-2026-13337 is a SQL injection vulnerability in the Hibernate ORM layer (CWE-564) that permits injection of malicious HQL queries when an authenticated user interacts with the device via the web service or web UI. Both vulnerabilities require local network access; the command injection requires high privileges and backup manipulation, while the SQL injection requires an authenticated user. Successful exploitation can result in device manipulation and unauthorized access to monitoring data. Patches are available in NetBotz 5 version 5.6.0 and later.

Affected products

  • Schneider Electric NetBotz 5 750 <=5.5.2
  • Schneider Electric NetBotz 5 755 <=5.5.2

CVE identifiers

  • CVE-2026-13337
  • CVE-2026-13336

Timeline

  • 2026-09-17: disclosed: CISA ICS Advisory ICSA-26-260-05 published
  • 2026-09-17: patched: Schneider Electric released NetBotz 5 version 5.6.0 containing fixes for both CVE-2026-13336 and CVE-2026-13337

References