216.73.217.22

CVE-2025-13316

· Published 19/11/2025 18:15 · Modified 25/11/2025 19:36

Labels: CVE-2025-13316 2025-11-19CVE-2025-13316CWE-321[email protected]

Essential information

Published
19/11/2025 18:15
Modified
25/11/2025 19:36
Author
Creator
CVSS
8.2 HIGH (v3) 8.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and gain administrator-level access to Twonky Server.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
lynxtechnology / twonky server cpe:2.3:a:lynxtechnology:twonky_server:8.5.2:*:*:*:*:*:*:*
linux / linux kernel cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
microsoft / windows cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

References