CVE-2025-8007
Severity CVSS v4.0:
HIGH
Type:
CWE-20
Input Validation
Publication date:
09/09/2025
Last modified:
17/09/2025
Description
A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent Forward Close operation can trigger a Major Non-Recoverable (MNFR) fault. This condition may lead to unexpected system crashes and loss of device availability.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:rockwellautomation:1756-en2tr_series_a_firmware:*:*:*:*:*:*:*:* | 7.001 (excluding) | |
| cpe:2.3:h:rockwellautomation:1756-en2tr_series_a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:1756-en2tr_series_b_firmware:*:*:*:*:*:*:*:* | 7.001 (excluding) | |
| cpe:2.3:h:rockwellautomation:1756-en2tr_series_b:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:1756-en2tr_series_c_firmware:*:*:*:*:*:*:*:* | 7.001 (excluding) | |
| cpe:2.3:h:rockwellautomation:1756-en2tr_series_c:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:1756-en4tr_firmware:*:*:*:*:*:*:*:* | 7.001 (excluding) | |
| cpe:2.3:h:rockwellautomation:1756-en4tr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:rockwellautomation:1756-en4trxt_firmware:*:*:*:*:*:*:*:* | 7.001 (excluding) | |
| cpe:2.3:h:rockwellautomation:1756-en4trxt:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



