CVE-2025-13315: Lynxtechnology Twonky Server
Critical severity, CVSS 9.8. EPSS: 32.5% chance of exploitation in the next 30 days.
Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.
Affected products
- Lynxtechnology Twonky Server: version 8.5.2 only
Published 2025-11-19. Last modified 2026-06-17.