CVE-2025-13315
Unauthenticated log access in Twonky Server
Vexday Risk Score
75High priority
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.3EPSS 31.9%KEV nãoPoC públicaNuclei simMetasploit simPatch —
Lifecycle
19 Nov 2025Published on NVD
07 Apr 2026Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Lynxtechnology · Twonky Serverpublic PoCs found — 1
githubgithub.com/0xBlackash/CVE-2025-13315★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →