ThreatCluster

Critical Twonky Server Vulnerabilities Allow Authentication Bypass

First seen 2 Dec 2025, 18:33 UTC GbhackersCybersecuritynewsCyberpress 30

Article Content

Browse articles
ThreatCluster

Security researchers at Rapid7 identified critical vulnerabilities in Twonky Server that allow attackers to bypass authentication mechanisms. An unprotected API endpoint can be exploited to leak encrypted admin passwords, potentially compromising user accounts. Users of Twonky Server are advised to take immediate action to secure their systems.