Technician monitors server racks and cybersecurity systems in a glowing data center.
Schneider Electric has published fixes for two vulnerabilities in NetBotz 5 Rack Monitor 750 and Wall Monitor 755 appliances running firmware 5.5.2 or earlier, and CISA republished the vendor advisory on September 17. Administrators should inventory NBRK0750 and NBWL0755 devices now, restrict their management interfaces to trusted administration networks, and plan a firmware update rather than treating this as a Windows patching issue.

The advisory, Schneider Electric security notice SEVD-2026-223-02, covers CVE-2026-13336 and CVE-2026-13337. These are devices commonly placed in server rooms, network closets, industrial facilities, and data centers to collect environmental alarms and video—not ordinary endpoint hardware. That placement makes their web interfaces, stored backup files, and integration credentials particularly sensitive: an appliance compromise can expose surveillance data or provide a foothold into the management network that operators often assume is isolated.

CISA’s publication is a republication of Schneider Electric’s August 11 advisory rather than a newly discovered flaw. The CVE records were published on September 1, and CISA’s September 17 posting raises visibility for an issue that facilities and infrastructure teams may otherwise miss.

Two flaws, two very different administrative paths​

CVE-2026-13336 is an OS command-injection vulnerability in the backup-restore process. Schneider Electric’s CVE description says a maliciously modified system backup can cause Linux operating-system commands to run when it is restored. The public CVSS 4.0 score is 7.3, rated High.

Its prerequisites matter. The score’s adjacent-network vector means the attack is not described as an internet-wide, unauthenticated drive-by compromise. It also requires high privileges and a malicious backup archive. In practical terms, an attacker would need to be positioned on the relevant local network and gain—or abuse—administrative access sufficient to place a tampered backup into the restoration workflow.

That does not make the bug harmless. Backups are frequently moved between administrators, stored on shared management systems, or kept for disaster recovery. A NetBotz restore image should therefore be treated as executable, security-sensitive material until every vulnerable appliance is updated. A backup obtained from email, a file share, a ticket attachment, or an uncertain former administrator should not be restored merely because it has the expected filename or came from an internal location.

CVE-2026-13337 is a SQL-injection flaw in the NetBotz database layer, described as an injection of a malicious Hibernate Query Language request through the web-service interface or Web UI. Schneider Electric assigns it a CVSS 4.0 score of 5.1, Medium. The CVE record indicates that a logged-in user with low privileges can trigger the condition over an adjacent network.

The difference is operationally important. The command-injection flaw is tied to restore operations and requires high privileges; the SQL-injection flaw is tied to a routine browser or web-service management path and requires a lower-privileged authenticated account. Organizations that have delegated monitoring access, retained former contractor accounts, or shared NetBotz credentials should review those accounts as part of the remediation work.

Firmware 5.5.2 and earlier are in scope​

Both CVEs affect NetBotz 5 firmware 5.5.2 and prior releases on the Rack Monitor 750 and Wall Monitor 755. Schneider Electric’s product documentation identifies the models as NBRK0750 and NBWL0755, respectively. The scope does not extend, on this evidence, to every APC or Schneider Electric network-management product; teams should avoid turning this advisory into a broad, untested fleet update.

The primary CVE record for CVE-2026-13336 identifies later releases as unaffected by setting the product’s default status to unaffected while marking versions through 5.5.2 as affected. That establishes the critical remediation boundary, but the public CISA republication does not clearly spell out a target firmware build in the text provided to administrators. Schneider Electric’s August security notice is the authoritative record for the actual package and upgrade instructions.

There is a practical trap for older appliances. Schneider Electric’s own support guidance, updated in 2026, says an appliance on firmware 5.3.4 or earlier must first be upgraded to 5.3.5 before it can successfully move to any 5.4.x or later firmware. Attempting to jump directly from 5.3.4 or older to a current fixed release can fail.

For change managers, that means the job may require a staged upgrade rather than a single maintenance-window upload:

  • Appliances on 5.3.4 or earlier need the documented intermediate move to 5.3.5 before proceeding to the current remediated firmware.
  • Appliances on 5.3.5 through 5.5.2 still require the security update, but do not face that particular pre-5.4.x upgrade dependency.
  • Every upgrade plan should include configuration backup, restoration testing, sensor and camera validation, and confirmation that the device resumes alert delivery after the reboot.

The advisory does not say whether live exploitation has been observed. CISA’s enrichment data for CVE-2026-13336 records exploitation as “none” and automation as “no,” but those fields are a prioritization signal, not a guarantee that the appliance is safe to leave unpatched—particularly for systems whose main purpose is alerting operators to water, smoke, temperature, or physical-access events.


Management-network exposure is the immediate control​

Schneider Electric and CISA both recommend keeping control and monitoring devices off the public internet and separating them from business networks. For NetBotz deployments, that advice should translate into a concrete review of where the Web UI and web-service interface are reachable—not a generic reminder to “use a firewall.”

Start by locating each NBRK0750 and NBWL0755 management address, its VLAN, and the systems permitted to talk to it. A device visible from user workstations, guest wireless networks, broad server subnets, or a VPN group larger than the facilities and infrastructure teams has a materially wider attack surface than the advisory’s adjacent-network metric might suggest.

Administrators should also check whether the appliance is discovered or managed through Schneider Electric Data Center Expert and whether monitoring platforms, scripts, or service accounts use its web-service interface. The SQL-injection issue puts extra weight on identifying accounts that can sign in but do not need administrative privileges. Disable dormant accounts, replace shared credentials with named access where the product supports it, and restrict management paths at the network layer.

Do not confuse a VPN with complete remediation. CISA’s standard guidance correctly notes that remote access should use secure methods, including VPNs, but a VPN merely moves the trust boundary. If a broad VPN population can reach NetBotz management addresses, the appliance remains exposed to any compromised device or inappropriate account inside that remote-access group.

Restore files deserve tighter handling​

The command-injection finding exposes a weak point that many infrastructure teams overlook: recovery media and configuration backups can carry active risk. The susceptible action is restoration of a maliciously altered system backup, so the safest interim control is to limit who can export, store, upload, and restore NetBotz backups.

Keep known-good backup images in controlled storage with restricted write access. Record the firmware version, appliance serial or asset identifier, backup date, and the administrator who created it. If possible, retain hashes generated at the time of export so a future restoration candidate can be checked against the archived record.

This is especially relevant for Windows-centric IT organizations because backups often end up on shared Windows file servers, administrative workstations, ticketing systems, or collaboration repositories. Those locations may have useful audit trails, but they also introduce many people and processes between backup creation and restore. A backup file from a shared drive is not automatically trusted simply because it resides on a corporate domain.

If an urgent restore is necessary before the fixed firmware is deployed, perform it only from a known-good, access-controlled backup and from a dedicated administration workstation on the management network. Then prioritize the firmware update immediately after service is restored.

Verify the device role before scheduling downtime​

NetBotz 750 and 755 appliances are not passive sensors. They can handle temperature, humidity, leak, smoke, vibration, door-contact, and video monitoring, so a reboot or failed update can temporarily interrupt alarms that facilities staff rely on. Schneider Electric says these devices store alarms and data locally for limited periods; deployments using multiple cameras and continuous image capture can exhaust retention sooner.

Before updating, identify what each appliance is watching and whether it triggers email, SNMP, or integration alerts into a service desk, building-management platform, or data-center monitoring console. Confirm a maintenance contact is watching the affected environment by another means while the NetBotz unit is unavailable.

After the update, validate more than the firmware version. Test the Web UI from the designated management host, verify sensor readings, trigger a non-disruptive alert where feasible, confirm downstream monitoring receives it, and ensure camera or video functions resume for installations that use them. The value of these devices is the alarm path; a successfully completed upload without a functioning alert path is not a completed remediation.

The immediate priority is clear: find NetBotz 5 750 and 755 units on firmware 5.5.2 or below, keep their management interfaces off broadly reachable networks, protect backup-restore workflows, and follow Schneider Electric’s staged upgrade requirement for systems older than 5.3.5.