CVE-2025-66631: CSLA .NET is vulnerable to Remote Code Execution via WcfProxy

Published Dec 8, 2025
·
Updated

Impact Versions of CSLA .NET prior to version 6 allow the use of WcfProxy. WcfProxy uses the NetDataContractSerializer (NDCS) which has known vulnerabilities that can allow remote execution of code during deserialization. NDCS itself is considered obsolete, and you should avoid using WcfProxy or upgrade to CSLA 6 or higher where this issue does not exist.

Patches CSLA .NET version 6 and higher do not use WCF or NetDataContractSerializer.

Workarounds If you are using a version CSLA .NET older than version 6, you should stop using WcfProxy in your data portal configuration. Doing this avoids the use of WCF and the NetDataContractSerializer, avoiding the vulnerability.

Other sources

CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSerializer (NDCS) and is vulnerable to remote code execution during deserialization. This vulnerability is fixed in version 6.0.0. To workaround this issue, remove the WcfProxy in data portal configurations.

MITRE

Affected Software

2 affected componentsFixes available
nuget/Csla<6.0.0
6.0.0
Cslanet Csla .net<6.0.0

Event History

Dec 8, 2025
Advisory Published
via GitHub·10:15 PM
Data Sourced
via GitHub·10:15 PM
DescriptionWeaknessAffected Software
Dec 9, 2025
CVE Published
via MITRE·03:18 AM
Data Sourced
via MITRE·03:18 AM
DescriptionWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
RemedyAffected Software
Aug 6, 58200
Event
via NVD·08:59 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-66631?

CVE-2025-66631 is considered a critical vulnerability due to its potential for remote code execution through deserialization.

2

How do I fix CVE-2025-66631?

To address CVE-2025-66631, upgrade to CSLA .NET version 6.0.0 or later, which removes the vulnerable WcfProxy functionality.

3

What versions are affected by CVE-2025-66631?

CVE-2025-66631 affects all versions of CSLA .NET prior to 6.0.0.

4

What are the risks associated with CVE-2025-66631?

The risks associated with CVE-2025-66631 include potential remote code execution and exploitation of the application by attackers.

5

Is WcfProxy safe to use in my application related to CVE-2025-66631?

WcfProxy is not safe to use in applications affected by CVE-2025-66631 due to its reliance on the vulnerable NetDataContractSerializer.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203