Security ID : QSA-21-10

Multiple Vulnerabilities in Twonky Server


  • Release date : April 16, 2021

  • Affected products: QNAP NAS running Twonky Server

Severity

Important

Status

Resolved


Summary

Two vulnerabilities have been reported to affect earlier versions of Twonky Server.


  • An improper access restriction vulnerability allows remote attackers to gain access to sensitive information, such as the administrator username and password for accessing Twonky Server settings.
  • A weak password obfuscation vulnerability allows remote attackers to decrypt passwords easily.

Both vulnerabilities combined allow remote attackers to gain access to all content accessible to the server.


The vendor released version 8.5.2 to address the vulnerabilities.


Recommendation

To fix the vulnerability, we recommend updating Twonky Server to the latest version.


Updating Twonky Server

  1. Log on to QTS as administrator.
  2. Open the App Center and then click .
  3. A search box appears.
  4. Type “Twonky Server” and then press ENTER.
    Twonky Server appears in the search results.
  5. Click Update.
    A confirmation message appears.
    Note: The Update button is not available if your Twonky Server is already up to date.
  6. Click OK.
    The application is updated.

Reference:

Lynx Technology Twonky Server Multiple Vulnerabilities

Revision History:
V2.0 (May 13, 2021) - The security update is available
V1.0 (April 16, 2021) - Published

仕様を選択

      もっと見る 閉じる

      当ページを他の国/地域で見る:

      気軽にお問い合わせ! show inquiry button
      open menu
      back to top