Description
An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.
INFO
Published Date :
2025-06-20T18:35:19.243Z
Last Modified :
2026-04-07T14:08:58.658Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2025-25037 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-25037.