CVE-2025-66631

Severity CVSS v4.0:
HIGH
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
09/12/2025
Last modified:
25/03/2026

Description

CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSerializer (NDCS) and is vulnerable to remote code execution during deserialization. This vulnerability is fixed in version 6.0.0. To workaround this issue, remove the WcfProxy in data portal configurations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cslanet:csla_.net:*:*:*:*:*:*:*:* 6.0.0 (excluding)