---
id: CVE-2025-7330
title: >-
  A cross-site request forgery security issue exists in the product and version
  listed
summary: >-
  A cross-site request forgery security issue exists in the product and version
  listed. The vulnerability stems from missing CSRF checks on the impacted form.
  This allows for unintended configuration modification if an attacker can
  convinc…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'
cwe:
  - CWE-352
vendor: rockwellautomation
product: 1783-natr_firmware
affected:
  - 1783-natr_firmware < 1.007
patched:
  - 1783-natr_firmware 1.007
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-7330'
references:
  - url: >-
      https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1756.html
    label: PSIRT@rockwellautomation.com
tags:
  - nvd
epss: 0.00206
epssPercentile: 0.09828
ingestedAt: '2026-10-08T11:31:27.378Z'
---

## Overview

A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted link.

## Affected

- `1783-natr_firmware < 1.007`

## Remediation

Upgrade past the affected range:

- `1783-natr_firmware 1.007`
