VORANT. Threat Intelligence Sign in Get the full feed

Schneider Electric NetBotz 5 flaws enable command execution

routine vulnerability manufacturingtechnology

Two vulnerabilities in Schneider Electric NetBotz 5 750/755 (≤5.5.2) allow OS command injection via malicious backup restore and HQL injection via web UI/API, fixed in 5.6.0.

Schneider Electric, via CISA ICS advisory ICSA-26-260-05, disclosed two vulnerabilities affecting NetBotz 5 750 and 755 environmental and security monitoring appliances, versions 5.5.2 and earlier. CVE-2026-13336 is an OS command injection flaw (CWE-78) that can execute arbitrary Linux OS commands when a maliciously modified system backup is restored. CVE-2026-13337 is a SQL/HQL injection vulnerability (CWE-564) in the Hibernate-backed NetBotz database, exploitable by an authenticated user via the web-service interface or web UI, allowing injection of malicious HQL queries.

Successful exploitation could result in arbitrary or remote code execution over the local network, device manipulation, and unauthorized data access — a significant risk given NetBotz devices are deployed for environmental and physical security monitoring across commercial facilities, critical manufacturing, and IT sectors worldwide. There is no indication of active in-the-wild exploitation; this is a vendor-disclosed advisory reported by Schneider Electric CPCERT.

Schneider Electric has released version 5.6.0 for both NetBotz 5 750 and 755, which remediates both vulnerabilities and requires a reboot upon installation. Defenders should verify version via the 'About NetBotz' GUI option post-update. Standard ICS hardening is recommended: isolate control/monitoring networks behind firewalls, avoid direct internet exposure, restrict backup restore operations to trusted/verified sources, and use VPNs with proper patching for remote access.

Mentioned in this report

Vulnerabilities CVE-2026-13336CVE-2026-13337

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-05

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free