← back
CVE-2025-25037criticalobserved exploitationCWE-200

Aquatronica Controller System Complete Information Disclosure

85Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.3epss 1.4%
from disclosure to weapon
Published on NVDJun 20
VulnCheckJun 20
exploitation probability
1.4%top 29% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.