Home
CRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
8.5.2
affected
Description
Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.
Problem types
CWE-420: Unprotected Alternate Channel
Product status
8.5.2
Credits
Ryan Emmons, Staff Security Researcher at Rapid7
References
www.rapid7.com/...ky-server-authentication-bypass-not-fixed/