CVE-2025-13316HIGH 8.1EPSS p83.6%

CVE-2025-13316CVE-2025-13316

Description

Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and gain administrator-level access to Twonky Server.

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS2.65% probability of exploitation · percentile 83.6% · 2026-06-18T12:00:27Z
Published2025-11-19
Last modified2025-11-25

Underlying weaknesses· 1

CWE-321

References

  1. https://www.rapid7.com/blog/post/cve-2025-13315-cve-2025-13316-critical-twonky-server-authentication-bypass-not-fixed/

1

TypeTargetConfidenceTier
WeaknessUse of Hard-coded Cryptographic Keycwe-3210%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-13315
CVE
CVE-2026-31986
CVE
CVE-2025-1393
CVE
CVE-2026-22906
CVE
CVE-2025-56577
CVE
CVE-2025-49216
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.