CVE-2025-14713
Exposed Dangerous Method in Synology C2 Identity Edge Server
Publication date: 2026-05-27
Last updated on: 2026-05-27
Assigner: Synology Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| synology | c2_identity_edge_server | From 1.76.0-0307 (inc) |
| synology | c2_identity_edge_server | From 1.76.0-0307 (exc) |
| synology | c2_identity_edge_server | 7.3 |
| synology | c2_identity_edge_server | 7.2.2 |
| synology | c2_identity_edge_server | 7.2.1 |
| synology | c2_identity_edge_server | 7.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-749 | The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
The vulnerability can have a significant impact as it allows remote attackers to access user credentials stored on the edge server. This can lead to unauthorized access to user accounts and potentially compromise sensitive information or systems that rely on these credentials.
Can you explain this vulnerability to me?
This vulnerability, identified as CVE-2025-14713, is an Exposed Dangerous Method or Function issue in the Synology C2 Identity Edge Server package in DSM versions before 1.76.0-0307. It allows remote attackers to obtain user credentials from the edge server without any privileges or user interaction.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The vulnerability allows remote attackers to obtain user credentials from the edge server, which could lead to unauthorized access to sensitive personal data.
Such unauthorized access and potential data exposure may impact compliance with data protection regulations like GDPR and HIPAA, which require safeguarding user credentials and personal information.
However, the provided information does not explicitly state the direct effects on compliance with these standards.
What immediate steps should I take to mitigate this vulnerability?
To mitigate the vulnerability CVE-2025-14713 in Synology C2 Identity Edge Server, you should upgrade the affected DSM package to version 1.76.0-0307 or later.
This update addresses the exposed dangerous method or function that allows remote attackers to obtain user credentials.
Affected DSM versions include 7.3, 7.2.2, 7.2.1, and 7.1, all of which require this upgrade.