VYPR
Vendor

Lynxtechnology

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2025-13315CriNov 19, 2025
    risk 0.69cvss 9.8epss 0.33

    Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

  • CVE-2025-13316HigNov 19, 2025
    risk 0.56cvss 8.1epss 0.03

    Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and gain…

  • CVE-2018-7171HigMar 30, 2018
    risk 0.54cvss 7.5epss 0.29

    Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all.

  • CVE-2018-7203MedMar 30, 2018
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all.

  • CVE-2018-9182MedJun 8, 2018
    risk 0.40cvss 6.1epss 0.01

    Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.

  • CVE-2018-9177MedJun 8, 2018
    risk 0.40cvss 6.1epss 0.01

    Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.