← Back to overview

A denial-of-service vulnerability (CVE-2025-10478) exists in the Rockwell Automation 1756-ENBT module, a ControlLogix EtherNet/IP bridge used to connect Logix 5000 controllers with Ethernet devices. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted CIP packet, causing the module to crash and requiring a manual restart to recover. The vulnerability is classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions) and carries a CVSS v3.1 score of 7.5 (HIGH) and a CVSS v4.0 score of 8.7 (HIGH). All versions of the 1756-ENBT module are affected. Rockwell Automation recommends upgrading to 1756-EN2T or 1756-EN4TR as the primary mitigation. The vulnerability affects critical infrastructure sectors including Critical Manufacturing, Food and Agriculture, Transportation Systems, and Water and Wastewater. No known public exploitation has been reported at the time of publication. The advisory was initially released on September 3, 2026, and was reported to CISA by Rockwell Automation.

Affected products

  • Rockwell Automation 1756-ENBT Module

Related CVE's

  • CVE-2025-10478

Categories

  • Critical Infrastructure
  • Mobile & IoT
  • Network Infrastructure