CISA published an advisory covering two vulnerabilities in Schneider Electric’s NetBotz 5 appliances, which provide video, door-contact, leak, smoke, vibration, temperature and humidity monitoring for data centers and industrial facilities. CVE-2026-13336 is an OS command-injection flaw reachable through a maliciously modified backup-restore file, rated 6.4 (Medium) on the CVSS v3.1 scale. CVE-2026-13337 is a SQL injection flaw in the appliance’s web interface, rated 4.6 (Medium).
Both vulnerabilities affect NetBotz software versions 5.5.2 and earlier. Schneider Electric has released version 5.6.0 to remediate both issues. CISA lists the affected sectors as Commercial Facilities, Critical Manufacturing and Information Technology, with unpatched devices at risk of arbitrary code execution, device manipulation or unauthorized data access.
Why it matters
NetBotz appliances are themselves security and environmental monitoring equipment installed inside data centers — a vulnerability in the monitor undermines the very physical-security function the device is deployed to provide.

Leave a Reply