← Back to browse · API

CVE-2025-13315

Severity
CRITICAL
CVSS
9.3
EPSS
0.32941
Risk score
48.73
CISA KEV
No
PoC
No
Published
2025-11-19
Modified
2025-11-19
First seen
2026-08-07
Aliases
EUVD-2025-198189, GHSA-X96R-V3VC-578H
Products
Lynxtechnology:Twonky Server 8.5.2
Sources
euvd EUVD-2025-198189

Description

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

References