CVE-2025-25037

CRITICAL EXPLOITED NUCLEI

Aquatronica Controller System <= 5.1.6 - Information Disclosure

Title source: nuclei
STIX 2.1

Exploitation Summary

CVE-2025-25037 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including LiquidWorm. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit targets an unauthenticated information disclosure vulnerability in Aquatronica Control System 5.1.6. It sends a crafted POST request to the tcp.php endpoint to leak plaintext passwords and network configuration.

Description

An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · pythonwebappshardware
https://www.exploit-db.com/exploits/52028

This exploit targets an unauthenticated information disclosure vulnerability in Aquatronica Control System 5.1.6. It sends a crafted POST request to the tcp.php endpoint to leak plaintext passwords and network configuration.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Aquatronica Control System 5.1.6 (Firmware: 5.1.6, Web: 2.0)
No auth needed
Prerequisites: Network access to the target device · tcp.php endpoint exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Aquatronica Controller System <= 5.1.6 - Information Disclosure
HIGHVERIFIEDby s4e-io
Shodan: html:"aquatronica"

References (5)

Core 5
Core References
Exploit, Third Party Advisory exploit third-party-advisory
https://www.exploit-db.com/exploits/52028
Third Party Advisory exploit third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5824.php
Various Sources third-party-advisory
https://fortiguard.fortinet.com/encyclopedia/ips/56008
Various Sources product
https://www.aquatronica.com

Scores

CVSS v4 9.3
EPSS 0.0210
EPSS Percentile 84.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2025-06-20
CWE
CWE-200
Status published
Products (1)
Aquatronica/Aquatronica Controller System < 5.1.6
Published Jun 20, 2025
Tracked Since Feb 18, 2026