Rockwell Automation 1783-NATR Cross-Site Request Forgery Vulnerability
Published Oct 14, 2025
7.0
HIGHCVSS 4.0
EPSS 0.21%
Description
A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted link.
Affected products
-
Affected
- Version 1.006 and prior
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Rockwell Automation | Comms - 1783-NATR | unaffected | Affected
|
- < 1.007
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 1.007 and later https://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-34191 Advisory
- https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1756.html Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-34191 | Advisory | |
| https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1756.html | Vendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data