« Volver al listado

Lynxtechnology

Lynxtechnology Twonky Server: vulnerabilidades y CVE

Lynxtechnology Twonky Server tiene 6 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses2
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-13316Alta (8.2)2.7%—19 nov 2025
Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static…
CVE-2025-13315Crítica (9.3)32%—19 nov 2025
Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username…
CVE-2018-9182Media (6.1)1.4%—8 jun 2018
Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
CVE-2018-9177Media (6.1)0.68%—8 jun 2018
Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.
CVE-2018-7203Media (6.1)2.3%—30 mar 2018
Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all.
CVE-2018-7171Alta (7.5)28%—30 mar 2018
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1098.002 Additional Email Delegate Permissions1
  3. T1552.001 Credentials In Files1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.