Remote Code Execution Vulnerability in Opto22 Groov Manage API on GRV-EPIC and groov RIO Products
CVE-2025-13087
What is CVE-2025-13087?
A security vulnerability has been identified in the Opto22 Groov Manage REST API, impacting GRV-EPIC and groov RIO products. This issue occurs when a POST request is made to a specific endpoint, allowing for the unsafe processing of header information that can be exploited. Attackers with administrative access can execute arbitrary commands with root privileges, posing significant security threats to affected systems. It is crucial for users of these products to evaluate their exposure and apply necessary mitigations to protect against potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
groov RIO GRV-R7-I1VAPM-3 0 < 4.0.3
groov RIO GRV-R7-MM1001-10 0 < 4.0.3
groov RIO GRV-R7-MM2001-10 0 < 4.0.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
