Schneider Electric NetBotz 5 750/755
September 17, 2026 · CISA (US-CERT) · Severity: CRITICAL
View CSAF Summary Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access. The following versions of Schneider Electric NetBotz 5 750/755 are affected: NetBotz 5 750 vers:intdot/<=5.5.2 (CVE-2026-13336, CVE-2026-13337) NetBotz 5 755 vers:intdot/<=5.5.2 (CVE-2026-13336, CVE-2026-13337) CVSS Vendor Equipment Vulnerabilities v3 6.4 Schneider Electric Schneider Electric NetBotz 5 750/755 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), SQL Injection: Hibernate Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: France Vulnerabilities Expand All + CVE-2026-13336 CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system commands when a system back up is restored that has been maliciously modified. View CVE Details Affected Products Schneider Electric NetBotz 5 750/755 Vendor:Schneider Electric Product Version:NetBotz 5 750 versions 5.5.2 and prior, NetBotz 5 755 Versions 5.5.2 and prior Product Status:fixed, known_affected Remediations Vendor fixVersion 5.6.0 of NetBotz 5 750/755 includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware Reboot needed: Upon install, the offer will automatically restart. A customer can validate a successful install by logging into the GUI...
Key Takeaways
- Schneider Electric products including NetBotz, Modicon M340, and PowerChute contain security vulnerabilities that could impact industrial control and building management systems.
- The breadth of affected Schneider Electric products demonstrates the challenge of securing diverse OT product portfolios across industrial and facility management environments.
- Organizations using Schneider Electric equipment should review the specific CVEs and apply available patches while monitoring for signs of exploitation in their OT environments.