Executive brief
A security vulnerability in the Synology C2 Identity Edge Server allows unauthorized individuals to remotely access and steal user login credentials. This component is used to manage identity and access control for corporate networks; a successful attack could lead to widespread account takeovers and unauthorized access to sensitive business data. Organizations using this package on Synology NAS devices should update immediately to prevent credential theft.
Technical details
The Synology C2 Identity Edge Server package contains an 'Exposed Dangerous Method or Function' vulnerability (CWE-749). This flaw allows a remote, unauthenticated attacker to interact with sensitive internal functions that should not be accessible over the network. By invoking these methods, an attacker can successfully extract user credentials stored on or processed by the edge server. The vulnerability was identified during the Pwn2Own 2025 competition. It affects multiple versions of DSM (7.1 through 7.3) and is resolved in version 1.76.0-0307 or later.
Affected products
- Synology C2 Identity Edge Server for DSM 7.1 before 1.76.0-0307
- Synology C2 Identity Edge Server for DSM 7.2.1 before 1.76.0-0307
- Synology C2 Identity Edge Server for DSM 7.2.2 before 1.76.0-0307
- Synology C2 Identity Edge Server for DSM 7.3 before 1.76.0-0307
Timeline
- 2025-12-15: advisory: Initial public release of Synology security advisory
- 2025-12-16: patched: Fixed release 1.76.0-0307 made available
- 2026-05-27: disclosed: Detailed vulnerability information and CVE assignment published