VDB

CVE-2025-7328

CVE-2025-7328 PUBLISHED CVSS 9.899999618530273 CRITICAL

Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result in potential denial-of-service, admin account takeover, or NAT rule modifications. Devices would no longer be able to communicate through NATR as a result of denial-of-service or NAT rule modifications. NAT rule modification could also result in device communication to incorrect endpoints. Admin account takeover could allow modification of configuration and require physical access to restore.

EPSS 0.05% · 16.1th percentile

Risk Scores

CVSS 4.0
9.899999618530273
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H
EPSS Score
0.05%
16.1th percentile

Affected Products

VendorProductVersions
Rockwell AutomationComms - 1783-NATRVersion 1.006 and prior
rockwellautomation1783-natr_firmware0

Timeline

  • Oct 14, 2025 CVE Published
  • Oct 14, 2025 CVE Updated
  • Oct 15, 2025 EPSS Score
  • Oct 15, 2025 PoC Published
  • Oct 21, 2025 EPSS Score
  • Oct 21, 2025 PoC Published
  • Oct 27, 2025 EPSS Score
  • Nov 2, 2025 EPSS Score
  • Nov 8, 2025 EPSS Score
  • Nov 15, 2025 EPSS Score
  • Nov 21, 2025 EPSS Score
  • Nov 27, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›