CVE-2025-7330
Severity CVSS v4.0:
HIGH
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
14/10/2025
Last modified:
30/10/2025
Description
A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted link.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:rockwellautomation:1783-natr_firmware:*:*:*:*:*:*:*:* | 1.007 (excluding) | |
| cpe:2.3:h:rockwellautomation:1783-natr:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



