VDB
CVE-2025-7330
CVE-2025-7330
PUBLISHED
CVSS 7 HIGH
A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted link.
EPSS 0.02% · 4.1th percentile
Risk Scores
CVSS 4.0
7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.02%
4.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| rockwellautomation | 1783-natr_firmware | 0 |
| Rockwell Automation | Comms - 1783-NATR | Version 1.006 and prior |
Timeline
- Oct 14, 2025 CVE Published
- Oct 14, 2025 CVE Updated
- Oct 15, 2025 EPSS Score
- Oct 21, 2025 EPSS Score
- Oct 21, 2025 PoC Published
- Oct 27, 2025 EPSS Score
- Nov 2, 2025 EPSS Score
- Nov 8, 2025 EPSS Score
- Nov 15, 2025 EPSS Score
- Nov 21, 2025 EPSS Score
- Nov 27, 2025 EPSS Score
- Dec 3, 2025 EPSS Score