Firmware is low-level software stored in nonvolatile memory on hardware devices that initializes, configures, and controls components before and alongside the operating system. It matters in enterprise environments because it underpins reliability, security controls, and lifecycle management for infrastructure and devices.
A vulnerability in Opto 22's GRV-EPIC and groov RIO devices allows remote command execution with root privileges. Affected firmware versions are prior to 4.0.3. A patch is available, and CISA recommends network security measures.
A vulnerability in Shelly Pro 4PM smart DIN rail switches prior to version 1.6 allows attackers to cause denial of service by exploiting a resource allocation flaw in the JSON parser. The issue has a CVSS v4 score of 8.3. Mitigations include software updates and network security measures.
Opto 22's groov View software and firmware versions prior to R4.5e and 4.0.3 respectively have a vulnerability exposing sensitive metadata such as API keys. The company has released patches and CISA advises network isolation and VPN use to mitigate potential exploitation risks.
Opto 22 has addressed a critical vulnerability in its GRV-EPIC and groov RIO products that could allow remote code execution with root privileges. Users are advised to update to firmware version 4.0.3. Recommended cybersecurity measures for organizations have been outlined by CISA.