Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.
References
| Link | Resource |
|---|---|
| https://www.rapid7.com/blog/post/cve-2025-13315-cve-2025-13316-critical-twonky-server-authentication-bypass-not-fixed/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-11-19 18:15
Updated : 2025-12-02 16:42
NVD link : CVE-2025-13315
Mitre link : CVE-2025-13315
CVE.ORG link : CVE-2025-13315
JSON object : View
Products Affected
microsoft
- windows
linux
- linux_kernel
lynxtechnology
- twonky_server
CWE
CWE-420
Unprotected Alternate Channel
