← back
CVE-2025-13315

Unauthenticated log access in Twonky Server

CVSS 9.3 CRITICALEPSS 31.9%CWE-420
Vexday Risk Score
75High priority
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.3EPSS 31.9%KEV nãoPoC públicaNuclei simMetasploit simPatch
Lifecycle
19 Nov 2025Published on NVD
07 Apr 2026Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →