CVE-2025-13315
PoC largeUnauthenticated API Auth Bypass in Twonky Server Leaks Admin Credentials
CVE-2025-13315 is an access control flaw (CWE-420) in Twonky Server 8.5.2 on Linux and Windows that allows an unauthenticated remote attacker to bypass authentication on the server's web service API. By sending requests to the API without valid credentials, the attacker can read a server log file and retrieve the administrator's username and encrypted password, which could be cracked offline or used against the admin interface. Anyone running the affected Twonky Server build is exposed, and per Rapid7 (the assigning CNA) the flaw was not yet fixed at the time of disclosure. There is no confirmed in-the-wild exploitation and the issue is not in CISA KEV, but a public PoC exists and EPSS assigns a high 32.5% probability of exploitation within 30 days (98th percentile). The same Rapid7 advisory also covers companion issue CVE-2025-13316 in Twonky Server.
What to do: Because Rapid7 reported the bug as not fixed at disclosure, monitor the Rapid7 advisory and Lynx Technology for a patched Twonky Server release and upgrade as soon as one is available. In the interim, restrict access to the Twonky web service API to trusted networks only (e.g., firewall rules limiting the default web port) and review access logs for unauthenticated API requests. Once patched, change the Twonky administrator password, since it may have been exposed in encrypted form, and review the same advisory for the companion CVE-2025-13316.
| LynxTechnology Twonky Server | 8.5.2 on Linux and Windows (no fixed release available at time of disclosure, per Rapid7) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.
- Vendors
- lynxtechnology
- Products
- twonky server
- Weakness
- CWE-420
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.