CVE-2025-14713: High severity Synology C2 Identity Edge Server vulnerability
Published May 27, 2026
·Updated
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.
Affected Software
6 affected components
Synology C2 Identity Edge Server<1.76.0-0307
All of the following
Synology C2 Identity Edge Server<1.76.0-0307
Any of the following
Synology Diskstation Manager=7.1
Synology Diskstation Manager=7.2.1
Synology Diskstation Manager=7.2.2
Synology Diskstation Manager=7.3
Event History
May 27, 2026
CVE Published
via MITRE·08:39 AM
Data Sourced
via MITRE·08:39 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-14713?
The severity of CVE-2025-14713 is classified as high with a score of 7.5.
2
How do I fix CVE-2025-14713?
To fix CVE-2025-14713, upgrade to Synology C2 Identity Edge Server version 1.76.0-0307 or later.
3
What impact does CVE-2025-14713 have on user credentials?
CVE-2025-14713 allows remote attackers to obtain user credentials from the exposed edge server.
4
Which software is affected by CVE-2025-14713?
CVE-2025-14713 affects the Synology C2 Identity Edge Server package.
5
When was CVE-2025-14713 published?
CVE-2025-14713 was published on May 27, 2026.