Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-13315 — CVE-2025-13315 | Kitploit
Tools/GitHubGitHub/0xblackash/cve-2025-13315
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingAuthenticationLearning & Education
GitHub0xblackash/cve-2025-13315

CVE-2025-13315

CVE-2025-13315

View Repository
55 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🛡️ CVE-2025-13315 - Critical Authentication Bypass in Twonky Server 8.5.2

Cybersecurity breach_ CVE-2025-13315 visualized

CVE CVSS 9.3 Twonky Server No Patch

An unauthenticated attacker can bypass API authentication, leak admin credentials from logs, and achieve full administrator access.


📋 Overview

CVE-2025-13315 is a critical access control flaw in Twonky Server 8.5.2 (Linux & Windows) discovered by Rapid7.

An attacker can access privileged RPC endpoints via an alternative routing path (/nmc/rpc/) that bypasses authentication checks. This allows leaking application log files containing the administrator's username and encrypted password.

Combined with CVE-2025-13316 (hardcoded Blowfish encryption keys), attackers can decrypt the credentials and gain full administrative control over the media server — including all stored media files.

⚠️ Important: The vendor (Lynx Technology) has stated that no patch is currently available.


🛠️ Vulnerability Details

AttributeDetails
CVE IDCVE-2025-13315
SeverityCritical
CVSS v4.0 Score9.3
VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H
Affected ProductTwonky Server 8.5.2
PlatformsLinux, Windows
PublishedNovember 19, 2025
Patch Status❌ Unpatched (No fix planned as of disclosure)

Root Cause

  • Previous fixes only protected the /rpc/ endpoint.
  • The /nmc/rpc/ prefix still allows unauthenticated access to sensitive endpoints like log_getfile.

🔥 Proof of Concept (PoC)

cve-2025-13315 1
GET /nmc/rpc/log_getfile HTTP/1.1
Host: target.twonkyserver.local

This request returns application logs that contain lines similar to:

cve-2025-13315
accessuser=admin
accesspwd=<encrypted_password>

The password can then be decrypted using the hardcoded Blowfish key (see CVE-2025-13316).


🧪 Exploitation Impact

  • ✅ Leak admin username + encrypted password
  • ✅ Decrypt credentials (paired with CVE-2025-13316)
  • ✅ Full administrator login
  • ✅ Complete control over all media files
  • ✅ Remote server shutdown / reconfiguration
  • ✅ Potential data exfiltration or ransomware deployment

🛡️ Mitigation & Recommendations

Since no official patch exists, follow these urgent steps:

  1. Isolate the server — Place Twonky Server behind a strict reverse proxy or WAF.
  2. Block vulnerable paths:
    • Block /nmc/rpc/log_getfile
    • Block all /nmc/rpc/ endpoints if possible
  3. Use CrowdSec / WAF rules — Rules already exist for vpatch-CVE-2025-13315.
  4. Change admin password to a strong unique value (if accessible).
  5. Consider alternatives — Migrate to modern DLNA/UPnP media servers (e.g., Jellyfin, Plex, or Emby) that receive regular security updates.
  6. Network segmentation — Never expose Twonky Server directly to the internet.

📚 References

  • Rapid7 Official Advisory
  • NVD Detail
  • GitHub Advisory (GHSA-x96r-v3vc-578h)
  • SiteGuarding Technical Analysis

📄 License

This repository is for educational and defensive security purposes only.


Made with ❤️ for the security community

Stay safe. Patch what you can. Segment what you can't.

Download Tool