彙總 lynxtechnology 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
歷史漏洞主要涉及 跨站腳本與路徑處理缺陷 等問題,部分漏洞可能導致 工作階段劫持,並影響 軟體部署與生產負載 相關場景。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2025-13316 | Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and gain administrator-level access to Twonky Server. | [email protected] | 8.2 | 2.65% | 2025-11-19 | 2026-06-17 |
| CVE-2025-13315 | Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password. | [email protected] | 9.3 | 31.94% | 2025-11-19 | 2026-06-17 |
| CVE-2018-9182 | Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section. | [email protected] | 6.1 | 1.38% | 2018-06-07 | 2026-06-16 |
| CVE-2018-9177 | Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen. | [email protected] | 6.1 | 0.68% | 2018-06-07 | 2026-06-16 |
| CVE-2018-7203 | Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all. | [email protected] | 6.1 | 2.42% | 2018-03-30 | 2026-06-16 |
| CVE-2018-7171 | Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all. | [email protected] | 7.5 | 28.73% | 2018-03-30 | 2026-06-16 |