CVE-2025-14713
Analyzed Analyzed - Analysis Complete
Exposed Dangerous Method in Synology C2 Identity Edge Server

Publication date: 2026-05-27

Last updated on: 2026-06-02

Assigner: Synology Inc.

Description
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-27
Last Modified
2026-06-02
Generated
2026-06-16
AI Q&A
2026-05-27
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
synology c2_identity_edge_server to 1.76.0-0307 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-749 The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Impact Analysis

The vulnerability can have a significant impact as it allows remote attackers to access user credentials stored on the edge server. This can lead to unauthorized access to user accounts and potentially compromise sensitive information or systems that rely on these credentials.

Executive Summary

This vulnerability, identified as CVE-2025-14713, is an Exposed Dangerous Method or Function issue in the Synology C2 Identity Edge Server package in DSM versions before 1.76.0-0307. It allows remote attackers to obtain user credentials from the edge server without any privileges or user interaction.

Mitigation Strategies

To mitigate the vulnerability CVE-2025-14713 in Synology C2 Identity Edge Server, you should upgrade the affected DSM package to version 1.76.0-0307 or later.

This update addresses the exposed dangerous method or function that allows remote attackers to obtain user credentials.

Affected DSM versions include 7.3, 7.2.2, 7.2.1, and 7.1, all of which require this upgrade.

Compliance Impact

The vulnerability allows remote attackers to obtain user credentials from the edge server, which could lead to unauthorized access to sensitive personal data.

Such unauthorized access and potential data exposure may impact compliance with data protection regulations like GDPR and HIPAA, which require safeguarding user credentials and personal information.

However, the provided information does not explicitly state the direct effects on compliance with these standards.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-14713. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart