Back

HIGH

Rockwell Automation Comms - 1783-NATR Stored Cross-Site Scripting Vulnerability

Published Oct 14, 2025

Description

A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from missing special character filtering and encoding. Successful exploitation requires an attacker to be able to update configuration fields behind admin login.

Affected products

Remediation

Vendor solution

Upgrade to version 1.007 and later https://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Rockwell
Published Oct 14, 2025
Updated Oct 14, 2025
Reserved Jul 7, 2025
CISA Vulnrichment
Updated Oct 14, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Rockwell
Published Oct 14, 2025
Updated Oct 14, 2025
Exploited since n/a
EUVD-2025-34189