← Vulnerability feed

Vulnerability record · CVE-2025-13315 · published 19 November 2025

CVE-2025-13315: Lynxtechnology twonky server vulnerability

Lynxtechnology · Twonky Server

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

9.3 CVSS 4.0 Critical EPSS 32% · top 1.7% CWE-420 · CWE-420
9.3CVSS 4.0 base score
32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-13315 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2025-13316Lynxtechnology twonky server vulnerabilityTwonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of t…EPSS 2.7%7.5CVE-2018-7171Lynxtechnology twonky server path traversal vulnerabilityDirectory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a ..…EPSS 28%6.1CVE-2018-9177Lynxtechnology twonky server cross-site scripting vulnerabilityTwonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.EPSS 0.68%6.1CVE-2018-9182Lynxtechnology twonky server cross-site scripting vulnerabilityTwonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.EPSS 1.4%6.1CVE-2018-7203Lynxtechnology twonky server cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the f…EPSS 2.3%9.8CVE-2025-54309CrushFTP AS2 validation flaw grants remote admin accessCrushFTP 10 before 10.8.5 and 11 before 11.3.4_23 mishandle AS2 validation when the DMZ proxy feature is not in use, letting remote attackers obtain …KEVEPSS 95%analysed10.0CVE-2023-20198Cisco IOS XE Web UI unauthenticated privilege escalation and implant deploymentCVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local priv…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2025-13315), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.