---
id: CVE-2025-7329
title: >-
  A Stored Cross-Site Scripting security issue exists in the affected product
  that could potentially allow a malicious user to view and modify sensitive
  data or make the webpage unavailable
summary: >-
  A Stored Cross-Site Scripting security issue exists in the affected product
  that could potentially allow a malicious user to view and modify sensitive
  data or make the webpage unavailable. The vulnerability stems from missing
  special cha…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: rockwellautomation
product: 1783-natr_firmware
affected:
  - 1783-natr_firmware < 1.007
patched:
  - 1783-natr_firmware 1.007
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-7329'
references:
  - url: >-
      https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1756.html
    label: PSIRT@rockwellautomation.com
tags:
  - nvd
epss: 0.00262
epssPercentile: 0.16487
ingestedAt: '2026-10-08T11:31:27.378Z'
---

## Overview

A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from missing special character filtering and encoding. Successful exploitation requires an attacker to be able to update configuration fields behind admin login.

## Affected

- `1783-natr_firmware < 1.007`

## Remediation

Upgrade past the affected range:

- `1783-natr_firmware 1.007`
