CVE-2025-7330

A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted link.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:rockwellautomation:1783-natr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:1783-natr:-:*:*:*:*:*:*:*

History

30 Oct 2025, 21:41

Type Values Removed Values Added
References () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1756.html - () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1756.html - Vendor Advisory
First Time Rockwellautomation
Rockwellautomation 1783-natr
Rockwellautomation 1783-natr Firmware
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:h:rockwellautomation:1783-natr:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:1783-natr_firmware:*:*:*:*:*:*:*:*

14 Oct 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-14 13:15

Updated : 2025-10-30 21:41


NVD link : CVE-2025-7330

Mitre link : CVE-2025-7330

CVE.ORG link : CVE-2025-7330


JSON object : View

Products Affected

rockwellautomation

  • 1783-natr_firmware
  • 1783-natr
CWE
CWE-352

Cross-Site Request Forgery (CSRF)