CVE-2025-34414
Entrust Instant Financial Issuance (IFI) Legacy Remoting Service .NET Remoting RCE
Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the Legacy Remoting Service that is enabled by default. The service registers a TCP remoting channel with SOAP and binary formatters configured at TypeFilterLevel=Full and exposes default ObjectURI endpoints such as logfile.rem, photo.rem, cwPhoto.rem, and reports.rem on a network-reachable remoting port. A remote, unauthenticated attacker who can reach the remoting port can invoke exposed remoting objects to read arbitrary files from the server and coerce outbound authentication, and may achieve arbitrary file write and remote code execution via known .NET Remoting exploitation techniques. This can lead to disclosure of sensitive installation and service-account data and compromise of the affected host.
| CWE | CWE-502 CWE-306 |
| Vendor | entrust corporation |
| Product | instant financial issuance (if) |
| Published | Dec 9, 2025 |
| Last Updated | Mar 23, 2026 |
Get instant alerts for entrust corporation instant financial issuance (if)
Be the first to know when new unknown vulnerabilities affecting entrust corporation instant financial issuance (if) are published โ delivered to Slack, Telegram or Discord.