CVE-2025-13315 is a critical access control vulnerability in Twonky Server 8.5.2 affecting Linux and Windows deployments. The flaw allows a remote, unauthenticated attacker to bypass authentication controls protecting the web service API and access a log file that should not be exposed. The leaked log data can disclose the administrator username and encrypted password. Based on the provided context, the issue is classified as an access control flaw and associated with CWE-420. The vulnerability is remotely exploitable with no authentication or user interaction required.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small PoC set for CVE-2025-13315 affecting Twonky Server 8.5.2. There are three files: a Python exploit script, a nuclei template, and a README. The Python script is the active exploit PoC: it accepts a target URL or IP, normalizes it, sends an unauthenticated GET request to /nmc/rpc/log_getfile, writes the returned log to a local file, and prints lines containing likely credential markers such as admin, password, accessuser, or accesspwd. It disables TLS verification to accommodate self-signed certificates commonly seen on embedded deployments. The nuclei YAML is a detection-oriented template that probes /nmc/rpc/log_getfile and /rpc/log_getfile, checks for HTTP 200, large response size, and Twonky-specific strings, then extracts possible usernames and encrypted passwords via regex. The README explains the vulnerability chain and broader impact, including that CVE-2025-13315 can expose encrypted admin credentials from logs and may be paired with CVE-2025-13316 for credential decryption and full admin access. Overall, this repository is a real but limited exploit/detection package focused on unauthenticated log disclosure rather than full end-to-end compromise.
This repository contains a working exploit for CVE-2025-13315 and CVE-2025-13316, targeting Twonky Server 8.5.2 on both Linux and Windows. The main file, CVE-2025-13315.py, is a Python script that performs a full authentication bypass by exploiting an unauthenticated web API endpoint (/nmc/rpc/log_getfile). The script retrieves a log file containing the admin username and an encrypted password, then uses hardcoded Blowfish keys (extracted from the server binaries) to decrypt the password, thus granting the attacker full administrative access. The exploit is fully remote, requires no credentials or user interaction, and is confirmed to work on real deployments. The README provides detailed usage instructions, mitigation advice, and context about the vulnerability's severity and impact. No patch is available from the vendor, and the exploit is considered operational and easy to use.
This repository contains a working proof-of-concept exploit for CVE-2025-13315 and CVE-2025-13316, targeting Twonky Server 8.5.2 on both Linux and Windows. The exploit (CVE-2025-13315.py) is a Python script that leverages an authentication bypass to access the /nmc/rpc/log_getfile endpoint without credentials. It retrieves a log file containing the admin username and an encrypted password, then uses hardcoded Blowfish keys (extracted from the server binaries) to decrypt the password, thus granting full administrative access. The README.md provides detailed context, usage instructions, and mitigation advice. The exploit is fully remote, requires no prior access, and is trivial to use against exposed Twonky Server instances. No patch is available from the vendor. The repository is well-structured, with a single exploit script and a comprehensive README.
This repository contains a single Metasploit auxiliary module targeting Twonky Server 8.5.2. The exploit leverages two vulnerabilities: an authentication bypass (CVE-2025-13315) that allows unauthenticated access to a privileged log file endpoint, and a static key credential encryption flaw (CVE-2025-13316) that enables decryption of admin credentials found in the logs. The module first verifies the target is running the correct Twonky Server version by requesting '/dev0/desc.xml'. It then accesses '/nmc/rpc/log_getfile' to retrieve logs, extracts the administrator username and encrypted password, and decrypts the password using a hardcoded Blowfish key. The result is the plaintext admin credentials, which are reported and stored as loot. The code is written in Ruby and is designed to be run within the Metasploit framework. No fake or detection-only code is present; this is a functional exploit module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
A vulnerability listed as a serious security flaw for the week. No further details provided in the content.
An access control/authentication bypass issue in Twonky Server 8.5.2 (Linux/Windows) that allows unauthenticated access to a log file, potentially exposing the administrator username and encrypted password.
A critical authentication bypass vulnerability in Twonky Server 8.5.2 allows unauthenticated attackers to access privileged web API endpoints and leak application logs containing encrypted administrator credentials.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.