Critical Twonky Server Vulnerabilities Allow Authentication Bypass
First seen 2 Dec 2025, 18:33 UTC
•

•30
Export
Article Content
Browse articles
Security researchers at Rapid7 identified critical vulnerabilities in Twonky Server that allow attackers to bypass authentication mechanisms. An unprotected API endpoint can be exploited to leak encrypted admin passwords, potentially compromising user accounts. Users of Twonky Server are advised to take immediate action to secure their systems.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.