An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Jun 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters. | |
Title | Aquatronica Controller System Complete Information Disclosure | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-06-20T18:35:19.243Z
Updated: 2025-06-20T18:35:19.243Z
Reserved: 2025-01-31T18:32:36.214Z
Link: CVE-2025-25037

No data.

Status : Received
Published: 2025-06-20T19:15:35.870
Modified: 2025-06-20T19:15:35.870
Link: CVE-2025-25037

No data.