CVE-2025-14713
Received Received - Intake
Exposed Dangerous Method in Synology C2 Identity Edge Server

Publication date: 2026-05-27

Last updated on: 2026-05-27

Assigner: Synology Inc.

Description
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-27
Last Modified
2026-05-27
Generated
2026-05-27
AI Q&A
2026-05-27
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 6 associated CPEs
Vendor Product Version / Range
synology c2_identity_edge_server From 1.76.0-0307 (inc)
synology c2_identity_edge_server From 1.76.0-0307 (exc)
synology c2_identity_edge_server 7.3
synology c2_identity_edge_server 7.2.2
synology c2_identity_edge_server 7.2.1
synology c2_identity_edge_server 7.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-749 The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :

The vulnerability can have a significant impact as it allows remote attackers to access user credentials stored on the edge server. This can lead to unauthorized access to user accounts and potentially compromise sensitive information or systems that rely on these credentials.


Can you explain this vulnerability to me?

This vulnerability, identified as CVE-2025-14713, is an Exposed Dangerous Method or Function issue in the Synology C2 Identity Edge Server package in DSM versions before 1.76.0-0307. It allows remote attackers to obtain user credentials from the edge server without any privileges or user interaction.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability allows remote attackers to obtain user credentials from the edge server, which could lead to unauthorized access to sensitive personal data.

Such unauthorized access and potential data exposure may impact compliance with data protection regulations like GDPR and HIPAA, which require safeguarding user credentials and personal information.

However, the provided information does not explicitly state the direct effects on compliance with these standards.


What immediate steps should I take to mitigate this vulnerability?

To mitigate the vulnerability CVE-2025-14713 in Synology C2 Identity Edge Server, you should upgrade the affected DSM package to version 1.76.0-0307 or later.

This update addresses the exposed dangerous method or function that allows remote attackers to obtain user credentials.

Affected DSM versions include 7.3, 7.2.2, 7.2.1, and 7.1, all of which require this upgrade.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart