Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-13315 +1 in the same advisory: …13316 | Unauthenticated API Auth Bypass in Twonky Server Leaks Admin Credentials CVE-2025-13315 is an access control flaw (CWE-420) in Twonky Server 8.5.2 on Linux and Windows that allows an unauthenticated remote attacker to bypass authentication on the server's web service API. By sending requests to the API without valid credentials, the attacker can read a server log file and retrieve the administrator's username and encrypted password, which could be cracked offline or used against the admin interface. Anyone running the affected Twonky Server build is exposed, and per Rapid7 (the assigning CNA) the flaw was not yet fixed at the time of disclosure. There is no confirmed in-the-wild exploitation and the issue is not in CISA KEV, but a public PoC exists and EPSS assigns a high 32.5% probability of exploitation within 30 days (98th percentile). The same Rapid7 advisory also covers companion issue CVE-2025-13316 in Twonky Server. Do: Because Rapid7 reported the bug as not fixed at disclosure, monitor the Rapid7 advisory and Lynx Technology for a patched Twonky Server release and upgrade as soon as one is available. In the interim, restrict access to the Twonky web service API to trusted networks only (e.g., firewall rules limiting the default web port) and review access logs for unauthenticated API requests. Once patched, change the Twonky administrator password, since it may have been exposed in encrypted form, and review the same advisory for the companion CVE-2025-13316. | 9.3 group max | 33% | PoC |
| large≈ tens of thousands of internet-exposed Twonky Server instances (total embedded installed base likely higher) | |
| CVE-2018-9182 +1 in the same advisory: …9177 | Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section. Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — | |
| CVE-2018-7171 +1 in the same advisory: …7203 | Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all. NVD description · AI analysis pending | 7.5 group max | 28% | PoC ×2 |
| — |