CVE-2025-13315

Publication date

2025-11-19 17:41:36

Family

rapid7

State

PUBLISHED

Description

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrators username and encrypted password.