Description
CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or webui.
Published: 2026-09-01
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection enabling malicious HQL execution
Action: Apply Patch
AI Analysis

Impact

This vulnerability allows a logged‑in user to inject arbitrary HQL queries into the NetBotz database via the web‑service interface or web UI. The flaw originates from improper sanitisation of user supplied input in Hibernate, permitting attackers to execute arbitrary database commands. The primary impact is potential data compromise and integrity loss, as attackers could read, modify, or delete records.

Affected Systems

Schneider Electric NetBotz 5 - 750/755 devices. No specific version restrictions are listed, so any installation of this product family potentially contains the flaw.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. Because the injection requires an authenticated session with the web service or UI, the attack vector is user‑based; attacker must first gain valid credentials. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting limited publicly known exploitation. Nonetheless, the capacity to execute arbitrary database queries represents a significant risk for confidentiality, integrity, and availability if exploited within a trusted session.

Generated by OpenCVE AI on September 1, 2026 at 15:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Schneider Electric NetBotz patch that resolves the HQL injection flaw.
  • Disable or restrict the web‑service and web UI functions that allow direct HQL query execution for untrusted inputs.
  • Review and revise the application to enforce strict input validation and use parameterised queries to prevent SQL injection.

Generated by OpenCVE AI on September 1, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Schneider-electric
Schneider-electric netbotz 5 - 750/755
Vendors & Products Schneider-electric
Schneider-electric netbotz 5 - 750/755

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability in NetBotz Database via Web Service
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or webui.
Weaknesses CWE-564
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Schneider-electric Netbotz 5 - 750/755
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2026-09-01T15:44:20.429Z

Reserved: 2026-06-25T13:48:11.990Z

Link: CVE-2026-13337

cve-icon Vulnrichment

Updated: 2026-09-01T15:44:17.389Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T14:17:24.563

Modified: 2026-09-01T20:52:39.973

Link: CVE-2026-13337

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T16:28:07Z

Weaknesses