CVE-2025-7328 Details
Description
Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result in potential denial-of-service, admin account takeover, or NAT rule modifications. Devices would no longer be able to communicate through NATR as a result of denial-of-service or NAT rule modifications. NAT rule modification could also result in device communication to incorrect endpoints. Admin account takeover could allow modification of configuration and require physical access to restore.
Multiple broken authentication vulnerabilities have been identified in the Rockwell Automation Comms 1783-NATR product, specifically in versions through 1.006. These vulnerabilities arise from missing authentication checks on critical functions, potentially leading to a denial-of-service, admin account takeover, or unauthorized modifications of NAT rules. Such NAT rule changes could disrupt device communication or redirect it to incorrect endpoints. The admin account takeover risk allows for configuration changes, with physical access required to restore the system.
Users can upgrade to version 1.007 or later to address these vulnerabilities. For those unable to upgrade, Rockwell Automation recommends following their security best practices.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1756.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rockwellautomation 1783-natr firmware | < 1.007 |
CPE
Remediation
| |
| rockwellautomation 1783-natr | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 29, 2025 | Initial Analysis | [email protected] |
| Oct 14, 2025 | New CVE Received | [email protected] |