CVE Database
/

CVE-2025-13315

Back to search

CVE-2025-13315

Published: Nov 19, 2025

Modified: Nov 19, 2025

PUBLISHED

Description

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

VendorProductVersions

Lynxtechnology

Twonky Server

affected
8.5.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now