CVE-2025-25037

CRITICAL EXPLOITED NUCLEI

Aquatronica Controller System <= 5.1.6 - Information Disclosure

Title source: nuclei

Description

An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · pythonwebappshardware
https://www.exploit-db.com/exploits/52028

Nuclei Templates (1)

Aquatronica Controller System <= 5.1.6 - Information Disclosure
HIGHVERIFIEDby s4e-io
Shodan: html:"aquatronica"

Scores

CVSS v4 9.3
EPSS 0.0210
EPSS Percentile 84.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H

Details

VulnCheck KEV 2025-06-20
CWE
CWE-200
Status published
Products (1)
Aquatronica/Aquatronica Controller System < 5.1.6
Published Jun 20, 2025
Tracked Since Feb 18, 2026