Twonky Server 8.5.2 on Linux and Windows contains a cryptographic weakness involving the use of hard-coded static cryptographic keys to protect the administrator password. According to the provided content, an attacker who obtains the encrypted administrator password can use knowledge of these static keys to decrypt the stored value and recover the plaintext password. With the recovered credentials, the attacker can authenticate to Twonky Server as an administrator and obtain administrator-level access.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a working exploit for CVE-2025-13315 and CVE-2025-13316, targeting Twonky Server 8.5.2 on both Linux and Windows. The main file, CVE-2025-13315.py, is a Python script that performs a full authentication bypass by exploiting an unauthenticated web API endpoint (/nmc/rpc/log_getfile). The script retrieves a log file containing the admin username and an encrypted password, then uses hardcoded Blowfish keys (extracted from the server binaries) to decrypt the password, thus granting the attacker full administrative access. The exploit is fully remote, requires no credentials or user interaction, and is confirmed to work on real deployments. The README provides detailed usage instructions, mitigation advice, and context about the vulnerability's severity and impact. No patch is available from the vendor, and the exploit is considered operational and easy to use.
This repository contains a single Metasploit auxiliary module targeting Twonky Server 8.5.2. The exploit leverages two vulnerabilities: an authentication bypass (CVE-2025-13315) that allows unauthenticated access to a privileged log file endpoint, and a static key credential encryption flaw (CVE-2025-13316) that enables decryption of admin credentials found in the logs. The module first verifies the target is running the correct Twonky Server version by requesting '/dev0/desc.xml'. It then accesses '/nmc/rpc/log_getfile' to retrieve logs, extracts the administrator username and encrypted password, and decrypts the password using a hardcoded Blowfish key. The result is the plaintext admin credentials, which are reported and stored as loot. The code is written in Ruby and is designed to be run within the Metasploit framework. No fake or detection-only code is present; this is a functional exploit module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in Twonky Server. Details not specified in the content, but it is listed as a serious security flaw for the week.
A cryptographic flaw in Twonky Server 8.5.2 for Linux and Windows involving hard-coded encryption keys allows attackers to decrypt administrator passwords and gain admin access.
A high-severity vulnerability in Twonky Server 8.5.2 where hardcoded Blowfish encryption keys are used for administrator password encryption, allowing attackers to decrypt leaked credentials and gain administrator access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.