Critical

Opto 22 GRV-EPIC and groov RIO

All CISA Advisories

Overview

The Opto 22 GRV-EPIC and groov RIO products are vulnerable to an OS Command Injection flaw that could allow remote attackers to execute arbitrary shell commands with root privileges. This vulnerability, identified as CVE-2025-13087, has a CVSS v4 score of 7.5, indicating a significant risk to affected systems.

Key Takeaways

  • Affected Systems: Affected products include GRV-EPIC-PR1 and GRV-EPIC-PR2 (Firmware versions prior to 4.0.3), groov RIO GRV-R7-MM1001-10, GRV-R7-MM2001-10, and GRV-R7-I1VAPM-3 (all with Firmware versions prior to 4.0.3). Vendor: Opto 22.
  • Action Required: Opto 22 has published a patch to address this vulnerability.
  • Timeline: Disclosed on November 20, 2025

Original Article Summary

View CSAF 1. EXECUTIVE SUMMARY CVSS v4 7.5 ATTENTION: Exploitable remotely Vendor: Opto 22 Equipment: GRV-EPIC-PR1, GRV-EPIC-PR2, groov RIO Vulnerability: Improper Neutralization of Special Elements used in an OS Command 2. RISK EVALUATION Successful exploitation of this vulnerability could result in the execution of arbitrary shell commands with root privileges. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS The following versions of GRV Programmable Logic Controllers are affected: GRV-EPIC-PR1 Firmware: Versions prior to 4.0.3 GRV-EPIC-PR2 Firmware: Versions prior to 4.0.3 groov RIO GRV-R7-MM1001-10 Firmware: Versions prior to 4.0.3 groov RIO GRV-R7-MM2001-10 Firmware: Versions prior to 4.0.3 groov RIO GRV-R7-I1VAPM-3 Firmware: Versions prior to 4.0.3 3.2 VULNERABILITY OVERVIEW 3.2.1 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE-78 A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code execution with root privileges. When a POST request is executed against the vulnerable endpoint, the application reads certain header details and unsafely uses these values to build commands, allowing an attacker with administrative privileges to inject arbitrary commands that execute as root. CVE-2025-13087 has been assigned to this vulnerability. A CVSS v3.1 base score of 6.2 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L). A CVSS v4 score has also been calculated for CVE-2025-13087. A base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N). 3.3 BACKGROUND CRITICAL INFRASTRUCTURE SECTORS: Critical Manufacturing COUNTRIES/AREAS DEPLOYED: Worldwide COMPANY HEADQUARTERS LOCATION: United States 3.4 RESEARCHER Nik Tsytsarkin, Ismail Aydemir, and Ryan Hall of Meta reported this vulnerability to CISA. 4. MITIGATIONS Opto 22 has published a patch to address this vulnerability and recommends that users upgrade to GRV-EPIC and groov RIO Firmware Version 4.0.3. Additional information is available from Opto 22 here. CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that a VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity. 5. UPDATE HISTORY November 20, 2025: Initial Publication

Impact

Affected products include GRV-EPIC-PR1 and GRV-EPIC-PR2 (Firmware versions prior to 4.0.3), groov RIO GRV-R7-MM1001-10, GRV-R7-MM2001-10, and GRV-R7-I1VAPM-3 (all with Firmware versions prior to 4.0.3). Vendor: Opto 22.

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Disclosed on November 20, 2025

Remediation

Opto 22 has published a patch to address this vulnerability. Users are recommended to upgrade to GRV-EPIC and groov RIO Firmware Version 4.0.3. Additional defensive measures include minimizing network exposure for control system devices, using firewalls, and employing secure remote access methods like VPNs.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, Patch, and 3 more.

Related Coverage

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107

Security Affairs

The Security Affairs Malware Newsletter discusses recent malware threats, including a backdoor introduced through compromised RubyGems like SleeperGem, Dendreo, and fastlane. These malicious packages can allow attackers to maintain persistent access to affected systems. Additionally, the report highlights the chaos caused by over 800 fake AI skills and MCP servers that delivered malware to unsuspecting users. The newsletter also mentions a ransomware variant called msaRAT that poses further risks. These developments are significant as they illustrate the evolving tactics used by cybercriminals, affecting developers and users who rely on these tools. Companies and users should remain vigilant and ensure their software sources are secure to prevent such incidents.

Jul 26, 2026

Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials

Security Affairs

Hackers have taken advantage of compromised hotel Wi-Fi gateways to trick users into entering their Microsoft 365 credentials on fake login pages. According to research from ReliaQuest's threat team, attackers have targeted hotels and conference centers, redirecting guests without their knowledge. This method avoids traditional phishing tactics like emails or attachments, making it particularly sneaky. Anyone using hotel Wi-Fi could be at risk, especially business travelers who often access sensitive accounts. This incident serves as a reminder for users to be cautious when logging into accounts over public networks and to verify the authenticity of login pages.

Jul 26, 2026

Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs

Iran-linked actors have been identified as targeting critical infrastructure in the United States, specifically focusing on water and energy control systems. This escalation raises alarms about the security of essential services that millions rely on. The attacks pose significant risks, as breaches in these systems could lead to disruptions in water supply and energy distribution, impacting daily life and public safety. The involvement of state-sponsored groups highlights the ongoing geopolitical tensions and the potential for cyber warfare to affect civilian infrastructure. Organizations managing these essential services need to enhance their security measures to defend against such sophisticated threats.

Jul 26, 2026

How to Secure AI Applications in Production

SCM feed for Latest

AI applications face significant security challenges at three critical points: system prompt integrity, output handling, and runtime visibility. These weaknesses can lead to various vulnerabilities, including data leaks or malicious outputs that could mislead users or systems. Organizations deploying AI solutions need to address these issues to protect sensitive information and ensure reliable performance. Failure to secure these aspects can result in serious consequences, including loss of trust from users and potential regulatory scrutiny. It’s crucial for companies to implement robust security measures at these control points to mitigate risks associated with AI deployment.

Jul 26, 2026

Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached

Help Net Security

Last week, it was reported that a pre-authentication remote code execution (RCE) vulnerability in ServiceNow was actively exploited in the wild. This vulnerability allows attackers to execute arbitrary code on affected systems without needing to authenticate, posing significant risks to organizations using the platform. In a separate incident, Hugging Face, a popular AI community, experienced a data breach, although details about the extent of the breach and the data compromised have not been fully disclosed. These incidents highlight ongoing security challenges for companies leveraging AI and cloud services, as they must remain vigilant against potential exploits that can have serious consequences for their operations and data integrity.

Jul 26, 2026

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

BleepingComputer

Gamers using Steam forums are facing a new threat from ClickFix attacks, where attackers pose as helpful users offering solutions to game or computer issues. However, these purported fixes actually contain XMRig cryptominers, which secretly install on victims' devices to mine cryptocurrency without their consent. This not only affects the performance of users' computers but can also lead to increased electricity costs and potential hardware damage. Anyone who frequents these forums should be cautious and avoid downloading or executing unknown files, as this type of malware can significantly degrade their system's performance. The situation highlights the need for vigilance in online communities, especially where users seek help for technical problems.

Jul 25, 2026