Synology-SA-25:18 C2 Identity Edge Server (PWN2OWN 2025)

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Important
Status
Resolved

Abstract

Synology has released a security update for the C2 Identity Edge Server package in DSM to address
ZDI-CAN-28325 :
      • CVE-2025-14713 allows remote attackers to obtain user credentials from the edge server.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
C2 Identity Edge Server for DSM 7.3 Critical Upgrade to 1.76.0-0307 or above.
C2 Identity Edge Server for DSM 7.2.2 Critical Upgrade to 1.76.0-0307 or above.
C2 Identity Edge Server for DSM 7.2.1 Critical Upgrade to 1.76.0-0307 or above.
C2 Identity Edge Server for DSM 7.1 Critical Upgrade to 1.76.0-0307 or above.

Mitigation

None

Detail

Acknowledgement

Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)

Revision

Revision Date Description
1 2025-12-15 Initial public release.