CVE-2025-7330

A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted link.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:rockwellautomation:1783-natr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1783-natr:-:*:*:*:*:*:*:*

History

30 Oct 2025, 21:41

Type Values Removed Values Added
CPE cpe:2.3:o:rockwellautomation:1783-natr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1783-natr:-:*:*:*:*:*:*:*
First Time Rockwellautomation
Rockwellautomation 1783-natr Firmware
Rockwellautomation 1783-natr
References () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1756.html - () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1756.html - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

14 Oct 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-14 13:15

Updated : 2025-10-30 21:41


NVD link : CVE-2025-7330

Mitre link : CVE-2025-7330

CVE.ORG link : CVE-2025-7330


JSON object : View

Products Affected

rockwellautomation

  • 1783-natr
  • 1783-natr_firmware
CWE
CWE-352

Cross-Site Request Forgery (CSRF)