Schneider Electric has fixed two defects in the small appliances that sit in server rooms, switch rooms and plant rooms and watch the conditions inside them: heat, humidity, water on the floor, smoke, vibration, doors left open, and video. The United States cyber agency republished the manufacturer's advisory on 17 September, which is how most operators outside Europe will see it.
Neither defect is reachable from the internet. Both need someone already on the same local network, and both need an account on the device. What makes one of them worth an operator's attention is where it sits: in the moment a saved configuration is restored onto the monitor. Restore a file that somebody has altered, and the device runs their commands.
Corrected firmware, meaning the software inside the box, is available now. So the work here is scheduling rather than scrambling. Whoever owns rack and room monitoring on a site, facilities, IT or the site engineer, this is the advisory that belongs to them.
The alarm that never fires
These monitors, sold under Schneider Electric's NetBotz name, earn their place on the quiet nights. They are what notices that the room cooling stopped at two in the morning, that a gland has started weeping onto a cable tray, that the door to the switch room has been standing open since the afternoon. Nobody watches them. That is the point of them.
The manufacturer's own summary of the risk is plain: an unpatched unit risks code of an attacker's choosing running on it from the local network, with manipulation of the device and unauthorised access to its data following from that.
The practical reading is about what a manipulated monitor stops doing. A monitor under someone else's control can be made to report a room that is fine. The alarm that does not fire is the expensive one: the failure that arrives as a dead switchgear cabinet rather than as a high temperature warning three hours earlier, and a call out on plant nobody had scheduled.
The second defect is narrower. Someone already logged in can push a crafted database query at the monitor through its web service interface or its web UI, the browser page an engineer uses to configure it. It scores lower than the first and it needs a valid login to begin with, which puts the risk squarely on sites where the commissioning contractor's account is still live.
One detail in the remediation belongs in the maintenance conversation rather than the security one: installing the corrected build restarts the unit by itself, and the running version is confirmed afterwards from the device's own interface. For a few minutes, the thing watching the room for smoke and water is not watching. In a data hall with a dozen other sensors, that is nothing. In a substation building or a mine's surface switch room where this box is the only instrument in the room, it is a gap that belongs in a planned slot rather than taken ad hoc.
The questions the restore path raises
The first defect turns a stored configuration backup into an input, and inputs have provenance. The question worth putting to whoever holds the maintenance record is where those backup files live, who can write to them, and whether anyone would notice if one changed. If the answer is a shared drive, or a laptop belonging to the integrator who commissioned the system years ago, that was a filing decision rather than a security one.
The second question is the account list. Both defects need someone authenticated on the device, so the exposure is shaped entirely by who still holds a login: installers, the building services contractor, the integrator, whoever was in the room during the last refit.
The third is ownership, and it is the one that tends to be unresolved. These appliances sit in the gap between IT and facilities. IT does not treat them as servers, facilities does not treat them as software, and the question is which of the two has the corrected build on a list with a date against it.
There is also a question the advisory does not answer. It records deployment worldwide and reaches well past the plant floor, into commercial buildings and IT estates. It says nothing about how many of those units sit on networks where an authenticated local attacker is a realistic proposition rather than a theoretical one. That judgement stays with the site.
The technical record
- Advisory: CISA ICSA-26-260-05, published 17 September 2026, a republication of Schneider Electric CPCERT advisory SEVD-2026-223-02, originally released 11 August 2026. CISA does not warrant the accuracy of advisories it republishes and points questions back to the vendor, which reported the defects.
- Affected: NetBotz 5 750 and NetBotz 5 755, versions 5.5.2 and prior.
- CVE-2026-13336: CWE-78, command injection. Restoring a maliciously modified system backup can cause Linux operating system commands to run. CVSS v3.1 base score 6.4, vector CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H.
- CVE-2026-13337: CWE-564, SQL injection via Hibernate. A user logged in through the web service interface or the web UI can inject a crafted HQL query into the device database. CVSS v3.1 base score 4.6, vector CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N.
- Both entries give an adjacent network attack vector and require privileges, rated high for the command injection and low for the database injection.
- Remediation: version 5.6.0 carries the fix for both and is available from the vendor's product firmware page. The install restarts the device automatically, and the running version is shown under the About NetBotz item.
- Sectors listed are commercial facilities, critical manufacturing and information technology, with deployment worldwide. The advisory closes with the usual segmentation and remote access guidance.
A configuration backup gets filed away as insurance and then forgotten, which is exactly what makes it useful to somebody else. The corrected build closes that path on these monitors. The habit it exposes, trusting a restore file because it came from your own device, is not particular to one vendor's box, and the record of where those files have been is either something a site can produce today or something it cannot.
Source
- cisa.gov/news-events/ics-advisories/icsa-26-260-05