CVE-2025-13315

CRITICAL EXPLOITED NUCLEI

Twonky Server Log Leak Authentication Bypass

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2025-13315 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including 0xBlackash, remmons-r7, including a Metasploit module auxiliary/gather/twonky_authbypass_logleak. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains a functional Python script that exploits CVE-2025-13315, an authentication bypass vulnerability in Twonky Server 8.5.2, allowing unauthenticated access to log files containing sensitive credentials. The script sends a GET request to the vulnerable endpoint and saves the leaked log for analysis.

Description

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

Exploits (2)

nomisec WORKING POC
by 0xBlackash · infoleak
https://github.com/0xBlackash/CVE-2025-13315

The repository contains a functional Python script that exploits CVE-2025-13315, an authentication bypass vulnerability in Twonky Server 8.5.2, allowing unauthenticated access to log files containing sensitive credentials. The script sends a GET request to the vulnerable endpoint and saves the leaked log for analysis.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Twonky Server 8.5.2
No auth needed
Prerequisites: Network access to the Twonky Server instance
devstral-2 · analyzed Apr 09, 2026 Full analysis →
metasploit WORKING POC
by remmons-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/twonky_authbypass_logleak.rb

This Metasploit module exploits an authentication bypass (CVE-2025-13315) in Twonky Server 8.5.2 to leak encrypted administrator credentials from logs, then decrypts them using hardcoded keys (CVE-2025-13316). It confirms vulnerability, extracts credentials, and outputs plaintext credentials.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Twonky Server 8.5.2
No auth needed
Prerequisites: Network access to Twonky Server on port 9000 · Twonky Server 8.5.2 running
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Twonky Server 8.5.2 on Linux and Windows - Log File Exposure
CRITICALVERIFIEDby pussycat0x

Scores

CVSS v3 9.8
EPSS 0.8399
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2025-12-15
CWE
CWE-420
Status published
Products (1)
lynxtechnology/twonky_server 8.5.2
Published Nov 19, 2025
Tracked Since Feb 18, 2026