Critical OS Command Injection in Schneider Electric NetBotz 5 750/755 (CVE‑2026‑13336, CVE‑2026‑13337) Risks Remote Code Execution
What It Is – Schneider Electric disclosed two medium‑severity flaws (CVE‑2026‑13336 and CVE‑2026‑13337) in the NetBotz 5 750/755 environmental‑monitoring appliances. The bugs allow an attacker to inject OS commands or SQL statements when a maliciously‑crafted backup is restored.
Exploitability – No public exploit has been observed, but the CVSS v3 score is 6.4 (High). Exploitation is feasible for anyone with network access to the device and the ability to supply a compromised backup file.
Affected Products – NetBotz 5 750 and NetBotz 5 755 firmware ≤ 5.5.2 (global deployments across commercial facilities, critical manufacturing, and IT environments).
Why It Matters for Trust & Control Assurance
- Vulnerability‑management control – The issue tests an organization’s ability to maintain an up‑to‑date inventory, apply patches promptly, and verify firmware integrity, a core control that maps to many frameworks (e.g., NIST CSF 2.0 Protect → Vulnerability Management).
- Evidence of due diligence – Demonstrating that you have continuous monitoring and documented remediation evidence provides a defensible audit trail for regulators and enterprise buyers.
- Supply‑chain risk – These devices sit in critical infrastructure; a compromise could be leveraged to manipulate environmental controls or exfiltrate data, underscoring the need for robust third‑party oversight.
Recommended Actions
- Inventory all NetBotz 5 750/755 units and verify firmware versions.
- Apply Schneider Electric’s remediation patch (upgrade to 5.5.3 or later) immediately.
- Enable integrity checks on backup files and restrict backup‑restore operations to authenticated administrators.
- Log all firmware‑upgrade and backup‑restore events; integrate these logs into your SIEM for continuous monitoring.
- Review your vulnerability‑management process to ensure timely detection of similar OS‑command‑injection flaws.
Source: CISA Advisory – ICSA‑26‑260‑05