← Back

Twonky Server

twonky_server

Vendor: Lynxtechnology • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lynxtechnology
1Twonky Server
Jun 17, 2026
Nov 19, 2025
8.2 HIGH· v4
8.1 HIGH· v3
N/A· v2
Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static k...Show more
Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and gain administrator-level access to Twonky Server.Show less
1Lynxtechnology
1Twonky Server
Jun 17, 2026
Nov 19, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username an...Show more
Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.Show less
1Lynxtechnology
1Twonky Server
Jun 17, 2026
Jun 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
1Lynxtechnology
1Twonky Server
Jun 17, 2026
Jun 8, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.
1Lynxtechnology
1Twonky Server
Jun 17, 2026
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all.
1Lynxtechnology
1Twonky Server
Jun 17, 2026
Mar 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all.