CVE 8.2 HIGH

Hard-coded encryption keys in Twonky Server_CVE-2025-13316

8.2 / 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and gain administrator-level access to Twonky Server.

Basic Information

ID CVE-2025-13316
Source rapid7
Published Nov 19, 2025 at 17:53
Modified Nov 19, 2025 at 18:19

Affected Product

Vendor Lynxtechnology
Product Twonky Server
Version 8.5.2
Affected Versions Lynxtechnology Twonky Server 8.5.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.