CVE-2025-13315: Lynxtechnology Twonky Server

Critical severity, CVSS 9.8. EPSS: 32.5% chance of exploitation in the next 30 days.

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

Affected products

Published 2025-11-19. Last modified 2026-06-17.