VYPR
Unrated severityNVD Advisory· Published Nov 19, 2025· Updated Nov 19, 2025

Unauthenticated log access in Twonky Server

CVE-2025-13315

Description

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.