Description
This module leverages an authentication bypass in Twonky Server 8.5.2. By exploiting an authorization flaw to access a privileged web API endpoint and leak application logs, encrypted administrator credentials are leaked (CVE-2025-13315). The exploit will then decrypt these credentials using hardcoded keys (CVE-2025-13316) and login as the administrator. Expected module output is a username and plain text password for the administrator account.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/gather/twonky_authbypass_logleakmsf undefined(twonky_authbypass_logleak) > show actions ...actions...msf undefined(twonky_authbypass_logleak) > set ACTION < action-name >msf undefined(twonky_authbypass_logleak) > show options ...show and set options...msf undefined(twonky_authbypass_logleak) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub