CVE-2025-66631

CRITICAL

CSLA .NET < 6.0.0 - Remote Code Execution via WcfProxy NetDataContractSerializer Deserialization

Title source: llm
STIX 2.1

Description

CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSerializer (NDCS) and is vulnerable to remote code execution during deserialization. This vulnerability is fixed in version 6.0.0. To workaround this issue, remove the WcfProxy in data portal configurations.

References (3)

Core 3
Core References
Issue Tracking x_refsource_misc
https://github.com/MarimerLLC/csla/issues/4001
Issue Tracking x_refsource_misc
https://github.com/MarimerLLC/csla/pull/4018

Scores

CVSS v3 9.8
EPSS 0.0282
EPSS Percentile 86.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (4)
cslanet/csla_.net < 6.0.0
marimer/csla_.net < 6.0.0
MarimerLLC/csla < 6.0.0
nuget/Csla 0 - 6.0.0NuGet
Published Dec 09, 2025
Tracked Since Feb 18, 2026