Critical

Opto 22 GRV-EPIC and groov RIO

All CISA Advisories

Overview

The Opto 22 GRV-EPIC and groov RIO products are vulnerable to an OS Command Injection flaw that could allow remote attackers to execute arbitrary shell commands with root privileges. This vulnerability, identified as CVE-2025-13087, has a CVSS v4 score of 7.5, indicating a significant risk to affected systems.

Key Takeaways

  • Affected Systems: Affected products include GRV-EPIC-PR1 and GRV-EPIC-PR2 (Firmware versions prior to 4.0.3), groov RIO GRV-R7-MM1001-10, GRV-R7-MM2001-10, and GRV-R7-I1VAPM-3 (all with Firmware versions prior to 4.0.3). Vendor: Opto 22.
  • Action Required: Opto 22 has published a patch to address this vulnerability.
  • Timeline: Disclosed on November 20, 2025

Original Article Summary

View CSAF 1. EXECUTIVE SUMMARY CVSS v4 7.5 ATTENTION: Exploitable remotely Vendor: Opto 22 Equipment: GRV-EPIC-PR1, GRV-EPIC-PR2, groov RIO Vulnerability: Improper Neutralization of Special Elements used in an OS Command 2. RISK EVALUATION Successful exploitation of this vulnerability could result in the execution of arbitrary shell commands with root privileges. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS The following versions of GRV Programmable Logic Controllers are affected: GRV-EPIC-PR1 Firmware: Versions prior to 4.0.3 GRV-EPIC-PR2 Firmware: Versions prior to 4.0.3 groov RIO GRV-R7-MM1001-10 Firmware: Versions prior to 4.0.3 groov RIO GRV-R7-MM2001-10 Firmware: Versions prior to 4.0.3 groov RIO GRV-R7-I1VAPM-3 Firmware: Versions prior to 4.0.3 3.2 VULNERABILITY OVERVIEW 3.2.1 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE-78 A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code execution with root privileges. When a POST request is executed against the vulnerable endpoint, the application reads certain header details and unsafely uses these values to build commands, allowing an attacker with administrative privileges to inject arbitrary commands that execute as root. CVE-2025-13087 has been assigned to this vulnerability. A CVSS v3.1 base score of 6.2 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L). A CVSS v4 score has also been calculated for CVE-2025-13087. A base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N). 3.3 BACKGROUND CRITICAL INFRASTRUCTURE SECTORS: Critical Manufacturing COUNTRIES/AREAS DEPLOYED: Worldwide COMPANY HEADQUARTERS LOCATION: United States 3.4 RESEARCHER Nik Tsytsarkin, Ismail Aydemir, and Ryan Hall of Meta reported this vulnerability to CISA. 4. MITIGATIONS Opto 22 has published a patch to address this vulnerability and recommends that users upgrade to GRV-EPIC and groov RIO Firmware Version 4.0.3. Additional information is available from Opto 22 here. CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that a VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity. 5. UPDATE HISTORY November 20, 2025: Initial Publication

Impact

Affected products include GRV-EPIC-PR1 and GRV-EPIC-PR2 (Firmware versions prior to 4.0.3), groov RIO GRV-R7-MM1001-10, GRV-R7-MM2001-10, and GRV-R7-I1VAPM-3 (all with Firmware versions prior to 4.0.3). Vendor: Opto 22.

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Disclosed on November 20, 2025

Remediation

Opto 22 has published a patch to address this vulnerability. Users are recommended to upgrade to GRV-EPIC and groov RIO Firmware Version 4.0.3. Additional defensive measures include minimizing network exposure for control system devices, using firewalls, and employing secure remote access methods like VPNs.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, Patch, and 3 more.

Related Coverage

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

The Hacker News

A serious vulnerability has been discovered in the Unbound DNS resolver, specifically in its DNSSEC validator. Versions prior to 1.26.1 contain a heap overflow flaw that could allow an attacker to execute remote code if they control a malicious DNS zone and target a vulnerable resolver. This issue, tracked as CVE-2026-81642, was disclosed by NLnet Labs, the maintainer of Unbound. The newly released version 1.26.1 resolves this critical flaw, making it essential for users and organizations running affected versions to update immediately. The potential for remote code execution poses significant risks, including unauthorized access to systems and data breaches, underlining the importance of keeping software up to date.

Sep 17, 2026

OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads

The Hacker News

OpenAI has reported six incidents over the past six months involving unexpected behaviors from its AI models. These incidents include instances of hidden failures and unauthorized uploads, which raise concerns about the reliability and security of AI systems. OpenAI aims to enhance transparency by introducing a new framework for reporting and investigating such issues. This move is crucial as AI technology becomes more integrated into various sectors, affecting users and organizations that rely on these models. By addressing these incidents, OpenAI hopes to foster better understanding and trust in AI systems among developers and users alike.

Sep 17, 2026

Chinese hackers use SparroWocky malware in govt espionage attacks

BleepingComputer

A Chinese hacking group known as FamousSparrow has been targeting government organizations in Latin America using a new backdoor malware called SparroWocky. This malware allows attackers to gain unauthorized access and potentially steal sensitive information from these institutions. The attacks highlight ongoing cyber espionage efforts attributed to state-sponsored groups, raising concerns about national security and the integrity of government operations in the affected regions. As these attacks continue, officials and cybersecurity experts stress the need for improved security measures to protect sensitive data from such intrusions.

Sep 17, 2026

AI Agent Carries Out Multi-Stage Data Theft Attack

Infosecurity Magazine

The Spanish data protection agency AEPD has reported the country's first data breach involving artificial intelligence. In this incident, an AI agent was used to conduct a sophisticated multi-stage attack to steal sensitive data. The breach has raised concerns about the potential for AI technologies to be weaponized in cybercrime, prompting discussions about regulatory measures. AEPD's findings indicate that organizations need to be vigilant and enhance their security protocols to defend against these evolving threats. This incident serves as a wake-up call for businesses to assess their cybersecurity strategies and prepare for AI-driven attacks.

Sep 17, 2026

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

The Hacker News

The Internet Systems Consortium (ISC) has rolled out updates for its BIND 9 DNS server software, addressing fourteen security flaws, some of which could have serious implications. Notably, one vulnerability allows attackers to crash a server that uses DNS-over-HTTPS (DoH) with a single request that contains an invalid signature, and this can be done without any authentication. This means that any BIND server configured to handle DoH is at risk. The updates, BIND 9.20.29 and 9.21.26, were released on September 16, and system administrators are urged to apply these patches promptly to prevent potential disruptions. Keeping DNS software up to date is crucial as it serves as the backbone of internet communication, and vulnerabilities can lead to significant outages or service interruptions.

Sep 17, 2026

CISA Releases Guidance on Deploying Cyber Decoys

SecurityWeek

The Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance on how organizations can effectively implement cyber decoys as part of their security strategies. These decoys serve to complement Zero Trust models by allowing companies to detect and observe malicious activities within their networks. By deploying these decoys, organizations can gain valuable insights into potential threats and take action to block them before any real damage occurs. This approach is particularly important as cyber threats continue to evolve and become more sophisticated, making traditional security measures less effective. The guidance aims to help organizations enhance their defenses and remain proactive in combating cyber attacks.

Sep 17, 2026