Opens in a new tab

Schneider Electric NetBotz 5 750/755 Vulnerabilities: What Operators Need to Do Now

  • Home
  • Blog
  • Schneider Electric NetBotz 5 750/755 Vulnerabilities: What Operators Need to Do Now
NetBotz 5 750/755 vulnerabilities exposed through a network-connected environmental monitoring device in a server

Schneider Electric has published firmware 5.6.0 for the NetBotz 5 750 and NetBotz 5 755 environmental and security monitors, closing two medium-severity flaws that allow OS command execution and SQL injection on the local network. Operators running version 5.5.2 or earlier should upgrade as soon as the maintenance window allows, because successful exploitation can lead to device manipulation and unauthorized data access inside equipment rooms and data closets.

What the NetBotz 5 750/755 actually does in a facility

The NetBotz 5 750 and 755 are physical-environment monitors built for IT and operational technology spaces. They watch temperature, humidity, water leaks, smoke, vibration, door contacts, and video feeds, and they report back so facilities teams can spot cooling failures, water ingress, or unauthorized access before damage spreads. Because they sit in the same network segment as servers, switches, and supervisory control gear, the appliances are a high-value target: a compromise gives an attacker visibility into the room and a foothold inside the local network.

Which NetBotz versions are affected

  • NetBotz 5 750, version 5.5.2 and prior: affected by CVE-2026-13336 and CVE-2026-13337.
  • NetBotz 5 755, version 5.5.2 and prior: affected by CVE-2026-13336 and CVE-2026-13337.

Both flaws ship in the same product line and the same firmware range, so inventory checks should cover both model numbers.

CVE-2026-13336: OS command injection during backup restore

CVE-2026-13336 is classified as CWE-78, improper neutralization of special elements used in an OS command, sometimes called OS command injection. The flaw is triggered when a system backup is restored that has been maliciously modified, allowing execution of arbitrary Linux operating system commands. CVSS 3.1 gives this issue a base score of 6.4 with the vector AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H: exploitation requires an adjacent network position and existing high privileges, no user interaction, and produces high impact to confidentiality and integrity.

Backup files are commonly moved between systems, emailed between admins, or stored on shared drives, so the practical risk depends on how those backup artifacts are handled. Treat NetBotz backup files as trusted input only when they were created and stored on systems that an attacker cannot reach.

CVE-2026-13337: SQL injection through the web service and web UI

CVE-2026-13337 is a SQL injection issue in the Hibernate layer of NetBotz, classified as CWE-564. A malicious user who is already logged into the NetBotz through the web service interface or the web UI can inject a malicious HQL query into the NetBotz database. CVSS 3.1 scores this flaw at 4.6, with the vector AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N, which means low attack complexity, low privileges required, and limited impact to confidentiality and integrity.

The vulnerability depends on having an authenticated session, so the real exposure is the value of the credentials that can reach the NetBotz interface. Default or shared admin accounts, service accounts with weak passwords, and credentials that survived a previous compromise all raise the practical severity well above the 4.6 base score.

How to remediate the NetBotz 5 750/755 vulnerabilities

Schneider Electric has released version 5.6.0 of NetBotz 5 750/755, which includes the fix for both CVE-2026-13336 and CVE-2026-13337. The firmware is available on the Schneider Electric product range download page. After installation the appliance restarts automatically, and the new version can be confirmed by logging into the GUI and selecting the ‘About NetBotz’ option, which displays the installed version. Schneider Electric’s underlying advisory is published as SEVD-2026-223-02, both in CSAF and PDF form, and the CISA publication that mirrors the vendor text is dated 2026-09-17.

Pre-update checklist for a safe rollout

  • Export a known-good configuration and a current backup from the device before starting the upgrade, and store those files on a system that the appliance cannot reach.
  • Verify the integrity of any backup file before a restore, and avoid restoring backup files received from outside the operations team.
  • Schedule the upgrade during a maintenance window, because the device restarts automatically when the new firmware is applied.
  • After the restart, log into the GUI and confirm the version under ‘About NetBotz’.

Network and access controls that reduce exposure

Schneider Electric’s published guidance for the NetBotz product family lines up with standard industrial control system hardening and is worth applying on top of the firmware update:

  • Keep the NetBotz appliance on a management or operations network that sits behind a firewall, isolated from the corporate business network.
  • Restrict physical access to the appliance and the cabinet it lives in, and never leave the device in a ‘Program’ or configuration mode when unattended.
  • Avoid connecting any programming or management laptop to the NetBotz network if that laptop has touched other networks without being cleaned first.
  • Scan removable media, including USB drives and CDs, before they are used in any node on the NetBotz network.
  • Block direct internet access to the appliance and to all control system devices, and require a current, patched VPN when remote access is necessary.

Defense-in-depth also includes rotating any local NetBotz credentials that may have been used on a vulnerable build, reviewing web UI and web service access logs for unusual queries, and confirming that logging from the appliance is being forwarded to a system that the same credentials cannot tamper with.

Where the affected appliances are typically deployed

Schneider Electric marks the NetBotz 5 750/755 as deployed across commercial facilities, critical manufacturing, and information technology sites worldwide, with the company headquartered in France. In practice, the appliances are most often found in data centers, network closets, server rooms, telecommunications huts, and small industrial control cabinets, which is also where a compromise would be hardest to spot because the device is treated as background infrastructure rather than as a server.

Operators who manage NetBotz appliances through Schneider Electric’s Industrial Cybersecurity Services, or through a regional Schneider Electric contact, can also request help with patching and configuration review directly from the vendor.

FAQ

What versions of NetBotz 5 750/755 are affected by the vulnerabilities?

NetBotz 5 750 versions 5.5.2 and prior, and NetBotz 5 755 versions 5.5.2 and prior, are affected by both CVE-2026-13336 and CVE-2026-13337.

How do operators fix the NetBotz 5 750/755 vulnerabilities?

Upgrade to version 5.6.0 of NetBotz 5 750/755, which is available from the Schneider Electric product range page. The device automatically restarts after install. Operators can confirm the new version by selecting the ‘About NetBotz’ option in the device GUI.

What can an attacker do if a vulnerable NetBotz 5 750/755 is not patched?

On the local network, an attacker could trigger Linux OS command execution through a maliciously modified backup restore, or inject a malicious HQL query through the web service or web UI, leading to device manipulation and unauthorized data access.


This article summarizes reporting from cisa.gov.

← All Articles