CVE-2025-8007

Severity CVSS v4.0:
HIGH
Type:
CWE-20 Input Validation
Publication date:
09/09/2025
Last modified:
17/09/2025

Description

A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent Forward Close operation can trigger a Major Non-Recoverable (MNFR) fault. This condition may lead to unexpected system crashes and loss of device availability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:rockwellautomation:1756-en2tr_series_a_firmware:*:*:*:*:*:*:*:* 7.001 (excluding)
cpe:2.3:h:rockwellautomation:1756-en2tr_series_a:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:1756-en2tr_series_b_firmware:*:*:*:*:*:*:*:* 7.001 (excluding)
cpe:2.3:h:rockwellautomation:1756-en2tr_series_b:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:1756-en2tr_series_c_firmware:*:*:*:*:*:*:*:* 7.001 (excluding)
cpe:2.3:h:rockwellautomation:1756-en2tr_series_c:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:1756-en4tr_firmware:*:*:*:*:*:*:*:* 7.001 (excluding)
cpe:2.3:h:rockwellautomation:1756-en4tr:-:*:*:*:*:*:*:*
cpe:2.3:o:rockwellautomation:1756-en4trxt_firmware:*:*:*:*:*:*:*:* 7.001 (excluding)
cpe:2.3:h:rockwellautomation:1756-en4trxt:-:*:*:*:*:*:*:*