ZeroHour

CVE-2025-13315

PoC large

Unauthenticated API Auth Bypass in Twonky Server Leaks Admin Credentials

CVSS 4.0
9.3 critical
EPSS
33%p98
Published
()
Modified
AI analysis

CVE-2025-13315 is an access control flaw (CWE-420) in Twonky Server 8.5.2 on Linux and Windows that allows an unauthenticated remote attacker to bypass authentication on the server's web service API. By sending requests to the API without valid credentials, the attacker can read a server log file and retrieve the administrator's username and encrypted password, which could be cracked offline or used against the admin interface. Anyone running the affected Twonky Server build is exposed, and per Rapid7 (the assigning CNA) the flaw was not yet fixed at the time of disclosure. There is no confirmed in-the-wild exploitation and the issue is not in CISA KEV, but a public PoC exists and EPSS assigns a high 32.5% probability of exploitation within 30 days (98th percentile). The same Rapid7 advisory also covers companion issue CVE-2025-13316 in Twonky Server.

What to do: Because Rapid7 reported the bug as not fixed at disclosure, monitor the Rapid7 advisory and Lynx Technology for a patched Twonky Server release and upgrade as soon as one is available. In the interim, restrict access to the Twonky web service API to trusted networks only (e.g., firewall rules limiting the default web port) and review access logs for unauthenticated API requests. Once patched, change the Twonky administrator password, since it may have been exposed in encrypted form, and review the same advisory for the companion CVE-2025-13316.

Affected
LynxTechnology Twonky Server8.5.2 on Linux and Windows (no fixed release available at time of disclosure, per Rapid7)
Estimated exposure
large≈ tens of thousands of internet-exposed Twonky Server instances (total embedded installed base likely higher) — Twonky Server is commonly OEM-bundled in NAS devices and media-sharing setups, and historical internet-wide scans of its web service have shown tens of thousands of publicly reachable instances, though the exact current count is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

Vendors
lynxtechnology
Products
twonky server
Weakness
CWE-420
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.