{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-13337/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-13336"},{"id":"CVE-2026-13337"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NetBotz 5 750 (\u003c= 5.5.2)","NetBotz 5 755 (\u003c= 5.5.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","ics","ot","cve-2026-13336","cve-2026-13337"],"_cs_type":"advisory","_cs_vendors":["Schneider Electric"],"content_html":"\u003cp\u003eSchneider Electric has identified multiple vulnerabilities affecting the NetBotz 5 750 and 755 security and environmental monitoring products, specifically in firmware versions 5.5.2 and earlier. The vulnerabilities, tracked as CVE-2026-13336 and CVE-2026-13337, present risks of arbitrary code execution and unauthorized data access. CVE-2026-13336 is an OS Command Injection vulnerability that allows for arbitrary code execution when a maliciously modified system backup file is restored. CVE-2026-13337 involves an SQL injection vulnerability within the Hibernate framework, which can be exploited by an attacker with access to the web service interface or web-UI to inject malicious HQL queries. These flaws reside in devices critical for monitoring environmental factors like temperature, humidity, and physical security. Successful exploitation could result in complete device compromise or unauthorized manipulation of the monitoring data collected by the units. Defenders should prioritize applying the vendor-provided firmware update to version 5.6.0.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains network access to the target NetBotz device management interface.\u003c/li\u003e\n\u003cli\u003eFor CVE-2026-13337, the attacker authenticates to the web-UI or web-service interface.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HQL query payload targeting the Hibernate database layer.\u003c/li\u003e\n\u003cli\u003eThe payload is injected through the web interface, exploiting the lack of input neutralization.\u003c/li\u003e\n\u003cli\u003eFor CVE-2026-13336, the attacker obtains or modifies a valid system backup file with embedded OS commands.\u003c/li\u003e\n\u003cli\u003eThe attacker initiates the \u0026quot;restore\u0026quot; function on the NetBotz device using the malicious backup.\u003c/li\u003e\n\u003cli\u003eThe device processes the restore, inadvertently executing the embedded OS commands within the Linux environment.\u003c/li\u003e\n\u003cli\u003eThe final objective is achieved, resulting in arbitrary code execution or unauthorized database modification.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows for remote or arbitrary code execution on NetBotz 5 750 and 755 hardware. Because these devices serve as critical environmental and physical security monitors for data centers and manufacturing facilities, compromise leads to the potential for data exfiltration, manipulation of security alerts, and the ability to pivot into wider industrial or information technology networks. The vulnerabilities affect organizations globally across the commercial facilities, critical manufacturing, and information technology sectors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of Schneider Electric NetBotz 5 750/755 to firmware version 5.6.0 immediately.\u003c/li\u003e\n\u003cli\u003eIsolate NetBotz monitoring devices behind firewalls and ensure they are not accessible from the public internet to mitigate the attack vector described in CVE-2026-13337.\u003c/li\u003e\n\u003cli\u003eImplement strict access control lists for the web-UI and web-service interfaces to restrict access to authorized management workstations only.\u003c/li\u003e\n\u003cli\u003eEnforce physical security controls for all NetBotz controllers, including housing units in locked cabinets to prevent tampering or unauthorized backup manipulation.\u003c/li\u003e\n\u003cli\u003eMonitor the integrity of system backup files and restrict the ability to perform system restores to verified administrative personnel.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-17T17:11:42Z","date_published":"2026-09-17T17:11:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-netbotz-vulnerabilities/","summary":"Schneider Electric NetBotz 5 750 and 755 devices are affected by OS command injection and Hibernate SQL injection vulnerabilities, enabling unauthorized code execution and database manipulation.","title":"Multiple Vulnerabilities in Schneider Electric NetBotz 5 750/755","url":"https://feed.craftedsignal.io/briefs/2026-09-netbotz-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-13337","version":"https://jsonfeed.org/version/1.1"}