Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint.
This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).
References
| Link | Resource |
|---|---|
| https://cert.pl/posts/2026/02/CVE-2025-14577 | Third Party Advisory |
| https://www.slican.pl/oferta/centrale-telefoniczne/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
No history.
Information
Published : 2026-02-24 14:16
Updated : 2026-03-02 14:10
NVD link : CVE-2025-14577
Mitre link : CVE-2025-14577
CVE.ORG link : CVE-2025-14577
JSON object : View
Products Affected
slican
- ipl-256.3u
- ipu-14.105.wm
- ipl-256.wm
- ipl-256_firmware
- ncp_firmware
- ipm-032_firmware
- ipm-032.2u
- ncp_server_cm400p.1bc
- ipm-032.wm
- ipu-14.103.wm
- ipu-14.105.1u
- ncp_server_cm300p
- ipu-14_firmware
- ncp_server_cm300p.1bc
- ncp_server_cm600p.1bc
CWE
CWE-306
Missing Authentication for Critical Function
