Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.
The vulnerability results from an access control error (CWE-420 – incomplete or bypassed authentication path) in the Twonky Server web service API interface. An attacker without any credentials can send an appropriately crafted request to the API and bypass the required authentication mechanisms. As a result, it is possible to download a log file containing sensitive data – the administrator's username and encrypted password. The obtained data can be used for further attacks, e.g., password cracking attempts.
An attacker can gain unauthorized access to the application log file and read the administrator account name and encrypted password from it, which may lead to complete takeover of the administrative account.
According to information in the vendor references, the vulnerability has not been fixed (not fixed). It is recommended to monitor the vendor's website (Lynx Technology) for patch releases and track publications available at the indicated Rapid7 address. Until a fix is released, it is recommended to restrict network access to the Twonky Server web interface only to trusted hosts (e.g., using firewall or network rules) and avoid exposing the service on public network interfaces.
Twonky Server version 8.5.2 running on Linux and Windows systems.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XLinux Kernel
OSLinuxall versionsLynxtechnology Twonky Server
APPLynxtechnology8.5.2Microsoft Windows
OSMicrosoftall versions
Related vulnerabilities
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit