CVE-2025-25037
CRITICAL EXPLOITED NUCLEIAquatronica Controller System <= 5.1.6 - Information Disclosure
Title source: nucleiDescription
An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.
Exploits (1)
exploitdb
WORKING POC
by LiquidWorm · pythonwebappshardware
https://www.exploit-db.com/exploits/52028
Nuclei Templates (1)
Aquatronica Controller System <= 5.1.6 - Information Disclosure
HIGHVERIFIEDby s4e-io
Shodan:
html:"aquatronica"
References (5)
Scores
CVSS v4
9.3
EPSS
0.0210
EPSS Percentile
84.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Details
VulnCheck KEV
2025-06-20
CWE
CWE-200
Status
published
Products (1)
Aquatronica/Aquatronica Controller System
< 5.1.6
Published
Jun 20, 2025
Tracked Since
Feb 18, 2026