← Advisories

Aquatronica Control System 5.1.6 Passwords Leak Vulnerability

Critical
Advisory ID
ZSL-2024-5824
Release Date
30 May 2024
Vendor
Aquatronica s.r.l. - https://www.aquatronica.com
Affected Version
Firmware: 5.1.6, Web: 2.0
Tested On
Apache/2.0.54 (Unix), PHP/5.4.17
Summary

Aquatronica's electronic AQUARIUM CONTROLLER is easy to use, allowing you to control all the electrical devices in an aquarium and to monitor all their parameters; it can be used for soft water aquariums, salt water aquariums or both simultaneously.

Description

The tcp.php endpoint on the Aquatronica controller is exposed to unauthenticated attackers over the network. This vulnerability allows remote attackers to send a POST request which can reveal sensitive configuration information, including plaintext passwords. This can lead to unauthorized access and control over the aquarium controller, compromising its security and potentially allowing attackers to manipulate its settings.

Proof of Concept
Disclosure Timeline
04.05.2024Vulnerability discovered.
07.05.2024Vendor contacted.
29.05.2024No response from the vendor.
30.05.2024Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
30.05.2024Initial release
01.07.2024Added reference [1], [2] and [3]
18.07.2025Added reference [4], [5] and [6]