An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology diskstation Manager
|
|
| CPEs | cpe:2.3:a:synology:c2_identity_edge_server:*:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:7.1:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:7.2.1:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:7.2.2:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:7.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Synology diskstation Manager
|
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology
Synology c2 Identity Edge Server |
|
| Vendors & Products |
Synology
Synology c2 Identity Edge Server |
Wed, 27 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Credential Retrieval via Exposed Method in Synology C2 Identity Edge Server |
Wed, 27 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server. | |
| Weaknesses | CWE-749 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: synology
Published: 2026-05-27T08:39:35.762Z
Updated: 2026-05-27T12:48:14.986Z
Reserved: 2025-12-15T06:27:33.147Z
Link: CVE-2025-14713
Updated: 2026-05-27T12:48:10.455Z
Status : Analyzed
Published: 2026-05-27T09:16:26.853
Modified: 2026-06-02T20:41:53.467
Link: CVE-2025-14713
No data.