CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-13315

CVSS 9.3v4.0pub. 2025-11-19upd. 2025-12-02

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

🤖 AI Analysis
How it works

The vulnerability results from an access control error (CWE-420 – incomplete or bypassed authentication path) in the Twonky Server web service API interface. An attacker without any credentials can send an appropriately crafted request to the API and bypass the required authentication mechanisms. As a result, it is possible to download a log file containing sensitive data – the administrator's username and encrypted password. The obtained data can be used for further attacks, e.g., password cracking attempts.

Impact

An attacker can gain unauthorized access to the application log file and read the administrator account name and encrypted password from it, which may lead to complete takeover of the administrative account.

Mitigation & patch

According to information in the vendor references, the vulnerability has not been fixed (not fixed). It is recommended to monitor the vendor's website (Lynx Technology) for patch releases and track publications available at the indicated Rapid7 address. Until a fix is released, it is recommended to restrict network access to the Twonky Server web interface only to trusted hosts (e.g., using firewall or network rules) and avoid exposing the service on public network interfaces.

Who is affected

Twonky Server version 8.5.2 running on Linux and Windows systems.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Linux Kernel

    OS
    Linux
    all versions
  • Lynxtechnology Twonky Server

    APP
    Lynxtechnology
    8.5.2
  • Microsoft Windows

    OS
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2024-7262CRITICAL9.3⚠ KEVPL ✓same product

Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit