Organizations should upgrade NetBotz 5 750 and 755 to firmware version 5.6.0, available from Schneider Electric's product page. Additionally, follow vendor recommendations: isolate control networks, use firewalls, restrict physical access, and avoid connecting programming software to untrusted networks.
Quick answers
What is CVE-2026-13337?
Organizations should upgrade NetBotz 5 750 and 755 to firmware version 5.6.0, available from Schneider Electric's product page. Additionally, follow vendor recommendations: isolate control networks, use firewalls, restrict physical access, and avoid connecting programming software to untrusted networks.
How severe is CVE-2026-13337?
high, CVSS 6.4
Is CVE-2026-13337 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-13337 be mitigated?
Organizations should upgrade NetBotz 5 750 and 755 to firmware version 5.6.0, available from Schneider Electric's product page. Additionally, follow vendor recommendations: isolate control networks, use firewalls, restrict physical access, and avoid connecting programming software to untrusted networks.
CVSS
6.4
Vendor
Schneider Electric
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
NetBotz 5 750, NetBotz 5 755
Mitigation
Organizations should upgrade NetBotz 5 750 and 755 to firmware version 5.6.0, available from Schneider Electric's product page. Additionally, follow vendor recommendations: isolate control networks, use firewalls, restrict physical access, and avoid connecting programming software to untrusted networks.
Schneider Electric has disclosed two vulnerabilities in its NetBotz 5 750 and 755 environmental monitoring devices. The flaws, tracked as CVE-2026-13336 (OS command injection) and CVE-2026-13337 (SQL injection), could allow an authenticated attacker to execute arbitrary Linux commands or inject malicious HQL queries, potentially leading to device manipulation and unauthorized data access. The vendor has released firmware version 5.6.0 to address both issues.