OS Command Injection Vulnerability in Schneider Electric Products
CVE-2026-13336
7.3HIGH
What is CVE-2026-13336?
A vulnerability exists in Schneider Electric products that allows for OS command injection via improperly neutralized inputs. This can occur when a system backup, previously compromised, is restored, enabling malicious actors to execute unauthorized commands on the Linux operating system.
Affected Version(s)
NetBotz 5 - 750/755 Versions 5.5.2 and prior