CVE-2025-34414
Last modified
CVE-2025-34414 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the Legacy Remoting Service that is enabled by default. The service registers a TCP remoting channel with SOAP and binary formatters configured at TypeFilterLevel=Full and exposes default ObjectURI endpoints such as logfile.rem, photo.rem, cwPhoto.rem, and reports.rem on a network-reachable remoting port. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the Legacy Remoting Service that is enabled by default. The service registers a TCP remoting channel with SOAP and binary formatters configured at TypeFilterLevel=Full and exposes default ObjectURI endpoints such as logfile.rem, photo.rem, cwPhoto.rem, and reports.rem on a network-reachable remoting port. A remote, unauthenticated attacker who can reach the remoting port can invoke exposed remoting objects to read arbitrary files from the server and coerce outbound authentication, and may achieve arbitrary file write and remote code execution via known .NET Remoting exploitation techniques. This can lead to disclosure of sensitive installation and service-account data and compromise of the affected host.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-34414?
How severe is CVE-2025-34414?
How do I fix CVE-2025-34414?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-34409MailEnable versions prior to 10.54 contain a reflected cross…6.1
- CVE-2025-3441Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-344101Panel versions 1.10.33 - 2.0.15 contain a cross-site reques…7.1
- CVE-2025-34411Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-34412Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-34413Legality WHISTLEBLOWING by DigitalPA contains a protection m…7.1
- CVE-2025-34415Rejected reason: This CVE ID was rejected because it was res…
- CVE-2025-34416MailEnable versions prior to 10.54 contain an unsafe DLL loa…7.8
- CVE-2025-34417MailEnable versions prior to 10.54 contain an unsafe DLL loa…7.8
- CVE-2025-34418MailEnable versions prior to 10.54 contain an unsafe DLL loa…7.8
- CVE-2025-34419MailEnable versions prior to 10.54 contain an unsafe DLL loa…7.8
- CVE-2025-3442This vulnerability exists in TP-Link Tapo H200 V1 IoT Smart…4.4
Are you affected by CVE-2025-34414?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
