CVE-2025-14713
Analyzed
Analyzed - Analysis Complete
Exposed Dangerous Method in Synology C2 Identity Edge Server
Publication date: 2026-05-27
Last updated on: 2026-06-02
Assigner: Synology Inc.
Description
Description
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| synology | c2_identity_edge_server | to 1.76.0-0307 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-749 | The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted. |