cve-2025-25037
CRITICAL CVSS 9.3 opencve
Description
An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.
Timeline
- Published
- 2025-06-20 19:15 UTC
- Last Modified
- 2026-06-17
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 4.0 | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H |
mitre | ||
| 4.0 | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
nvd | ||
| 4.0 | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H |
opencve |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"advisories": [
{
"id": "EUVD-2025-18781",
"source": "euvd",
"title": "An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.",
"url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-18781"
}
],
"cve": "CVE-2025-25037",
"enrichment": {
"analysis": {
"en": {
"generated_at": "2026-04-28T11:13:19.573647+00:00",
"value": {
"mitigation_remediation": [
"Upgrade to firmware 5.1.7 or later and web interface 2.1 or later to remove the vulnerable endpoint.",
"If a patch is not yet available, block or disable access to the tcp.php endpoint using firewall rules or by modifying the web server configuration to require authentication.",
"Review system logs and audit credentials to detect any unauthorized usage and ensure that user accounts follow secure password practices."
],
"summary": {
"action": "Immediate Patch",
"impact": "Information disclosure leading to full system compromise"
},
"threat_synthesis": {
"affected_systems": "Aquatronica Controller System firmware versions 5.1.6 and earlier, and web interface versions 2.0 and earlier, are vulnerable. Devices running those versions are at risk until an update is applied.",
"description_and_impact": "An information disclosure vulnerability in Aquatronica Controller System allows remote attackers to retrieve sensitive configuration data, including plaintext administrative credentials, by accessing the unprotected tcp.php endpoint. The exposed credentials can enable full control over the system, allowing manipulation of connected devices and aquarium parameters.",
"risk_and_exploitability": "With a CVSS score of 9.3 and EPSS of 2%, the vulnerability is high severity and considered likely to be exploited. The exploit requires no authentication and can be performed from anywhere with network access to the device, making it a remote attack vector. Since it is not listed in KEV, no known public exploit has been reported to CISA, but the combination of broad accessibility and critical credentials means this flaw could lead to a full compromise of affected systems."
}
}
}
},
"created": "2026-04-28T11:15:26.098806+00:00",
"updated": "2026-04-28T11:15:26.098817+00:00",
"vendors": []
},
"epss": {
"score": 0.01574
},
"mitre": {
"cpes": [
"cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:*"
],
"created": "2025-06-20T18:35:19.243000+00:00",
"description": "An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {
"score": 9.3,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H"
}
},
"mitre_repo_path": "cves/2025/25xxx/CVE-2025-25037.json",
"references": [
"https://fortiguard.fortinet.com/encyclopedia/ips/56008",
"https://vulncheck.com/advisories/aquatronica-controller-system-credential-leak",
"https://www.aquatronica.com",
"https://www.exploit-db.com/exploits/52028",
"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5824.php"
],
"title": "Aquatronica Controller System Complete Information Disclosure",
"updated": "2026-07-28T01:47:56.966000+00:00",
"vendors": [
"aviatrix",
"aviatrix$PRODUCT$controller"
],
"weaknesses": [
"CWE-200"
]
},
"nvd": {
"cpes": [],
"created": "2025-06-20T19:15:35.870000+00:00",
"description": "An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {
"score": 9.3,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"nvd_repo_path": "2025/CVE-2025-25037.json",
"references": [
"https://fortiguard.fortinet.com/encyclopedia/ips/56008",
"https://vulncheck.com/advisories/aquatronica-controller-system-credential-leak",
"https://www.aquatronica.com",
"https://www.exploit-db.com/exploits/52028",
"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5824.php"
],
"title": null,
"updated": "2026-06-17T09:00:10.840000+00:00",
"vendors": [],
"weaknesses": [
"CWE-200"
]
},
"opencve": {
"changes": [
{
"created": "2025-06-20T19:00:00+00:00",
"data": [
{
"details": {
"new": "An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.",
"old": null
},
"type": "description"
},
{
"details": {
"new": "Aquatronica Controller System Complete Information Disclosure",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-200"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": [
"https://fortiguard.fortinet.com/encyclopedia/ips/56008",
"https://vulncheck.com/advisories/aquatronica-controller-system-credential-leak",
"https://www.aquatronica.com",
"https://www.exploit-db.com/exploits/52028",
"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5824.php"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV4_0": {
"score": 9.3,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "c272fde2-86e1-40fc-a7ce-61cb531a2441"
},
{
"created": "2025-06-23T21:15:00+00:00",
"data": [
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "poc",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "6a4448f3-969f-471f-b5ac-db7d5fd12190"
},
{
"created": "2026-07-28T02:30:00+00:00",
"data": [
{
"details": [
"aviatrix",
"aviatrix$PRODUCT$controller"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"aviatrix",
"aviatrix$PRODUCT$controller"
],
"removed": []
},
"type": "vendors"
}
],
"id": "de075822-3d97-46ea-8658-ed321ff4047d"
}
],
"cpes": {
"data": [
"cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:*"
],
"providers": [
"mitre"
]
},
"created": {
"data": "2025-06-20T18:35:19.243000+00:00",
"provider": "mitre"
},
"description": {
"data": "An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {},
"provider": null
},
"cvssV4_0": {
"data": {
"score": 9.3,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H"
},
"provider": "mitre"
},
"epss": {
"data": {
"score": 0.01574
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "poc",
"Technical Impact": "partial"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://fortiguard.fortinet.com/encyclopedia/ips/56008",
"https://vulncheck.com/advisories/aquatronica-controller-system-credential-leak",
"https://www.aquatronica.com",
"https://www.exploit-db.com/exploits/52028",
"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5824.php"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "Aquatronica Controller System Complete Information Disclosure",
"provider": "mitre"
},
"updated": {
"data": "2026-07-28T01:47:56.966000+00:00",
"provider": "mitre"
},
"vendors": {
"data": [
"aviatrix",
"aviatrix$PRODUCT$controller"
],
"providers": [
"mitre"
]
},
"weaknesses": {
"data": [
"CWE-200"
],
"providers": [
"mitre",
"nvd"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2025-06-20T18:35:19.243000+00:00",
"description": "An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "poc",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"references": [],
"title": "Aquatronica Controller System Complete Information Disclosure",
"updated": "2025-06-23T20:33:07.611000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2025/25xxx/CVE-2025-25037.json",
"weaknesses": []
}
}
Enrichment data
Aggregated bundle (all enrichments)