Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux linux Kernel
|
|
| CPEs | cpe:2.3:a:lynxtechnology:twonky_server:8.5.2:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux linux Kernel
|
|
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Lynxtechnology Lynxtechnology twonky Server Microsoft Microsoft windows |
|
| Vendors & Products |
Linux
Linux linux Lynxtechnology Lynxtechnology twonky Server Microsoft Microsoft windows |
Wed, 19 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password. | |
| Title | Unauthenticated log access in Twonky Server | |
| Weaknesses | CWE-420 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: rapid7
Published: 2025-11-19T17:41:36.996Z
Updated: 2025-11-19T18:20:50.718Z
Reserved: 2025-11-17T15:07:40.828Z
Link: CVE-2025-13315
Updated: 2025-11-19T18:20:47.162Z
Status : Analyzed
Published: 2025-11-19T18:15:47.843
Modified: 2025-12-02T16:42:19.270
Link: CVE-2025-13315
No data.