CVE Vulnerabilities

CVE-2025-13315

Unprotected Alternate Channel

Published: Nov 19, 2025 | Modified: Nov 19, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrators username and encrypted password.

Weakness

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Potential Mitigations

References