CVE-2025-7330

Severity CVSS v4.0:
HIGH
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
14/10/2025
Last modified:
30/10/2025

Description

A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted link.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:rockwellautomation:1783-natr_firmware:*:*:*:*:*:*:*:* 1.007 (excluding)
cpe:2.3:h:rockwellautomation:1783-natr:-:*:*:*:*:*:*:*