CVE-2025-13084

HIGH

Groov View API - Info Disclosure

Title source: llm
STIX 2.1

Description

The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators.

Scores

CVSS v3 7.6
EPSS 0.0006
EPSS Percentile 18.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1230
Status published
Products (3)
Opto 22/groov View Server R1.0a - R4.5d
Opto 22/GRV-EPIC-PR1 Firmware < 4.0.3
Opto 22/GRV-EPIC-PR2 Firmware < 4.0.3
Published Nov 26, 2025
Tracked Since Feb 18, 2026