CVE-2025-13084 Details
Description
The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators.
A privilege escalation vulnerability has been identified in the Opto 22 groov View API, specifically in the users endpoint. This endpoint, which requires an Editor role to access, returns a list of all users along with their associated metadata, including API keys. Notably, the API keys of Administrators are also exposed. The vulnerability is present in groov View Server for Windows versions 3.3a through 4.5d, as well as GRV-EPIC-PR1 and GRV-EPIC-PR2 Firmwares prior to 4.0.3.
Opto 22 has released a patch for this vulnerability. Users are advised to upgrade to groov View Server for Windows Version 4.5e and GRV-EPIC Firmware Version 4.0.3. Additional information can be found on the Opto 22 website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 26, 2025CISA-ADP
Assessed Nov 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-329-04.json | [email protected] | AdvisoryBundleRemedy |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-329-04 | [email protected] | AdvisoryBundleRemedy |
| https://www.opto22.com/support/resources-tools/knowledgebase/kb91325 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1230 | Exposure of Sensitive Information Through Metadata | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Opto 22 groov View Server | All versions |
CPE
Remediation
| |
| Opto 22 GRV-EPIC-PR1 Firmware | All versions |
CPE
Remediation
| |
| Opto 22 GRV-EPIC-PR2 Firmware | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 26, 2025 | New CVE Received | [email protected] |
Volerion