CVE Vulnerabilities

CVE-2025-13315

Unprotected Alternate Channel

Published: Nov 19, 2025 | Modified: Dec 02, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrators username and encrypted password.

Weakness

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Affected Software

NameVendorStart VersionEnd Version
Twonky_serverLynxtechnology8.5.2 (including)8.5.2 (including)

Potential Mitigations

References