CVE-2025-14577
Received
Received - Intake
PHP Function Injection in Slican Devices Enables Remote Code Execution
Publication date: 2026-02-24
Last updated on: 2026-03-02
Assigner: CERT.PL
Description
Description
Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint.
This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| slican | ncp_firmware | to 1.24.0190 (exc) |
| slican | ipl-256_firmware | to 6.61.0010 (exc) |
| slican | ipm-032_firmware | to 6.61.0010 (exc) |
| slican | ipu-14_firmware | to 6.61.0010 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |