CVE-2025-7329

A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from missing special character filtering and encoding. Successful exploitation requires an attacker to be able to update configuration fields behind admin login.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:rockwellautomation:1783-natr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1783-natr:-:*:*:*:*:*:*:*

History

30 Oct 2025, 21:43

Type Values Removed Values Added
First Time Rockwellautomation
Rockwellautomation 1783-natr Firmware
Rockwellautomation 1783-natr
References () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1756.html - () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1756.html - Vendor Advisory
CPE cpe:2.3:o:rockwellautomation:1783-natr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1783-natr:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8

14 Oct 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-14 13:15

Updated : 2025-10-30 21:43


NVD link : CVE-2025-7329

Mitre link : CVE-2025-7329

CVE.ORG link : CVE-2025-7329


JSON object : View

Products Affected

rockwellautomation

  • 1783-natr
  • 1783-natr_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')