Lynxtechnology's vulnerability profile centers on its Twonky Server media streaming and file-serving product, a narrowly scoped offering that has attracted significant public exploit development. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code, driven by recurring weakness classes including cross-site scripting, path traversal, hard-coded cryptographic keys, and unprotected alternate channels that are characteristic of networked media services with legacy authentication and input-handling patterns. Defenders should prioritize patching this vendor's advisories and restrict network exposure of affected instances; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lynxtechnology over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13315CRITICAL Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file | Nov 19, 2025 | 9.8 | 74 | NO | YES |
CVE-2018-7171HIGH Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase p | Mar 30, 2018 | 7.5 | 50 | NO | YES |
CVE-2025-13316HIGH Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator pass | Nov 19, 2025 | 8.1 | 44 | NO | YES |
CVE-2018-7203MEDIUM Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/se | Mar 30, 2018 | 6.1 | 32 | NO | YES |
CVE-2018-9182MEDIUM Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section. | Jun 8, 2018 | 6.1 | 19 | NO | NO |
CVE-2018-9177MEDIUM Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen. | Jun 8, 2018 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lynxtechnology.
Media articles that mention a CVE ID that affects a product developed by Lynxtechnology — matched by CVE ID, not by vendor name.