CVE-2025-25037 Scanner
CVE-2025-25037 Scanner - Information Disclosure vulnerability in Aquatronica Controller System
Used 2.8k times · 5.9k assets checked · domain, subdomain, ipv4
An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.
CVE-2025-25037 Scanner - Information Disclosure vulnerability in Aquatronica Controller System
Used 2.8k times · 5.9k assets checked · domain, subdomain, ipv4
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →