CVE List

CVE-2025-13315

Severe 9.8

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

Published November 19, 2025.

Affected software

Get alerts for Lynxtechnology Twonky Server

Reference links