Description
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.
Published: 2026-05-27
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Synology C2 Identity Edge Server’s DSM package contains an exposed dangerous method that allows a remote attacker to retrieve stored user credentials. The vulnerability is a representation of a “Dangerous Method or Function” flaw and is classified as CWE‑749. An attacker who can reach the exposed API can download full credential data, likely including passwords or other authentication tokens, undermining both confidentiality and integrity of user identities.

Affected Systems

Any Synology C2 Identity Edge Server running DSM prior to version 1.76.0-0307 is affected. The vulnerability resides in the C2 Identity Edge Server package and affects all installations on that platform with the specified older package version.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, reflecting the significant damage a successful exploitation could cause. Although the EPSS score is not available, the vulnerability’s remote nature and ability to expose credentials mean that exploitation is plausible, especially in environments where the edge server is exposed to potential attackers. The vulnerability is not currently listed in CISA’s KEV catalog, but that does not diminish its inherent risk. The likely attack vector is remote, achieved via the exposed method or function accessed over the network, with no local privilege escalation needed.

Generated by OpenCVE AI on May 27, 2026 at 10:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Synology DSM package to 1.76.0‑0307 or later, which removes the exposed method and fixes the credential exposure flaw.
  • Restrict network exposure of the C2 Identity Edge Server by configuring firewall rules or a VPN so that only trusted IP ranges can reach the service.
  • Audit access logs for unusual credential retrieval activity and ensure that only authorized administrative accounts have permission to query the edge server API.

Generated by OpenCVE AI on May 27, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 11:15:00 +0000

Type Values Removed Values Added
Title Remote Credential Retrieval via Exposed Method in Synology C2 Identity Edge Server

Wed, 27 May 2026 09:00:00 +0000

Type Values Removed Values Added
Description An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.
Weaknesses CWE-749
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-05-27T08:39:35.762Z

Reserved: 2025-12-15T06:27:33.147Z

Link: CVE-2025-14713

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-27T09:16:26.853

Modified: 2026-05-27T09:16:26.853

Link: CVE-2025-14713

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T11:00:13Z

Weaknesses