Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint.


This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).

Project Subscriptions

Vendors Products
Ipl-256.3u Subscribe
Ipl-256.wm Subscribe
Ipl-256 Firmware Subscribe
Ipm-032.2u Subscribe
Ipm-032.wm Subscribe
Ipm-032 Firmware Subscribe
Ipu-14.103.wm Subscribe
Ipu-14.105.1u Subscribe
Ipu-14.105.wm Subscribe
Ipu-14 Firmware Subscribe
Ncp Firmware Subscribe
Ncp Server Cm300p Subscribe
Ncp Server Cm300p.1bc Subscribe
Ncp Server Cm400p.1bc Subscribe
Ncp Server Cm600p.1bc Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 02 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Slican ipl-256.3u
Slican ipl-256.wm
Slican ipl-256 Firmware
Slican ipm-032.2u
Slican ipm-032.wm
Slican ipm-032 Firmware
Slican ipu-14.103.wm
Slican ipu-14.105.1u
Slican ipu-14.105.wm
Slican ipu-14 Firmware
Slican ncp Firmware
Slican ncp Server Cm300p
Slican ncp Server Cm300p.1bc
Slican ncp Server Cm400p.1bc
Slican ncp Server Cm600p.1bc
CPEs cpe:2.3:h:slican:ipl-256.3u:-:*:*:*:*:*:*:*
cpe:2.3:h:slican:ipl-256.wm:-:*:*:*:*:*:*:*
cpe:2.3:h:slican:ipm-032.2u:-:*:*:*:*:*:*:*
cpe:2.3:h:slican:ipm-032.wm:-:*:*:*:*:*:*:*
cpe:2.3:h:slican:ipu-14.103.wm:-:*:*:*:*:*:*:*
cpe:2.3:h:slican:ipu-14.105.1u:-:*:*:*:*:*:*:*
cpe:2.3:h:slican:ipu-14.105.wm:-:*:*:*:*:*:*:*
cpe:2.3:h:slican:ncp_server_cm300p.1bc:-:*:*:*:*:*:*:*
cpe:2.3:h:slican:ncp_server_cm300p:-:*:*:*:*:*:*:*
cpe:2.3:h:slican:ncp_server_cm400p.1bc:-:*:*:*:*:*:*:*
cpe:2.3:h:slican:ncp_server_cm600p.1bc:-:*:*:*:*:*:*:*
cpe:2.3:o:slican:ipl-256_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:slican:ipm-032_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:slican:ipu-14_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:slican:ncp_firmware:*:*:*:*:*:*:*:*
Vendors & Products Slican ipl-256.3u
Slican ipl-256.wm
Slican ipl-256 Firmware
Slican ipm-032.2u
Slican ipm-032.wm
Slican ipm-032 Firmware
Slican ipu-14.103.wm
Slican ipu-14.105.1u
Slican ipu-14.105.wm
Slican ipu-14 Firmware
Slican ncp Firmware
Slican ncp Server Cm300p
Slican ncp Server Cm300p.1bc
Slican ncp Server Cm400p.1bc
Slican ncp Server Cm600p.1bc
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 25 Feb 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Slican
Slican ipl
Slican ipm
Slican ipu
Slican ncp
Vendors & Products Slican
Slican ipl
Slican ipm
Slican ipu
Slican ncp

Tue, 24 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Feb 2026 14:00:00 +0000

Type Values Removed Values Added
Description Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).
Title PHP Function Injection in Slican NPC/IPL/IPM/IPU
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-02-24T15:00:45.355Z

Reserved: 2025-12-12T13:28:43.671Z

Link: CVE-2025-14577

cve-icon Vulnrichment

Updated: 2026-02-24T15:00:34.176Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-24T14:16:21.333

Modified: 2026-03-02T14:10:29.920

Link: CVE-2025-14577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-25T11:39:51Z

Weaknesses