CVE-2025-13087 Details
Description
A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code execution with root privileges. When a POST request is executed against the vulnerable endpoint, the application reads certain header details and unsafely uses these values to build commands, allowing an attacker with administrative privileges to inject arbitrary commands that execute as root.
A remote code execution vulnerability has been identified in the Opto 22 Groov Manage REST API, specifically in GRV-EPIC and groov RIO products, all versions prior to 4.0.3. The vulnerability allows an attacker with administrative privileges to inject arbitrary commands that are executed with root privileges. This exploitation occurs when a POST request is sent to a vulnerable endpoint, where the application improperly processes certain header values to construct command executions.
Opto 22 has released a patch for this vulnerability. Users are advised to upgrade to GRV-EPIC and groov RIO firmware version 4.0.3 or later. Additional information can be found on the Opto 22 website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 20, 2025CISA-ADP
Assessed Nov 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-324-03.json | [email protected] | AdvisoryBundleRemedy |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-324-03 | [email protected] | AdvisoryRemedy |
| https://www.opto22.com/support/resources-tools/knowledgebase/kb91326 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Opto 22 GRV-EPIC-PR1 | >= 3.2.0, <= 4.0.2 (semver) |
CPE
Remediation
| |
| Opto 22 GRV-EPIC-PR2 | >= 3.2.0, <= 4.0.2 (semver) |
CPE
Remediation
| |
| Opto 22 groov RIO GRV-R7-MM1001-10 | All versions |
CPE
Remediation
| |
| Opto 22 groov RIO GRV-R7-MM2001-10 | >= 3.2.0, <= 4.0.2 (semver) |
CPE
Remediation
| |
| Opto 22 groov RIO GRV-R7-I1VAPM-3 | >= 3.2.0, <= 4.0.2 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 20, 2025 | New CVE Received | [email protected] |
Volerion