CVE-2025-13084: Opto 22 Groov View Server

High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.

The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators.

Affected products

  • Opto 22 Groov View Server: from R1.0a, up to and including R4.5d
  • Opto 22 Grv-Epic-PR1 Firmware: up to and including 4.0.3
  • Opto 22 Grv-Epic-PR2 Firmware: up to and including 4.0.3

Published 2025-11-26. Last modified 2026-06-17.