S
lican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).
References
| Link | Resource |
|---|---|
| https://cert.pl/posts/2026/02/CVE-2025-14577 | Third Party Advisory |
| https://www.slican.pl/oferta/centrale-telefoniczne/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
02 Mar 2026, 14:10
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:slican:ncp_server_cm400p.1bc:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ncp_server_cm300p.1bc:-:*:*:*:*:*:*:* cpe:2.3:o:slican:ncp_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:slican:ncp_server_cm600p.1bc:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ncp_server_cm300p:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ipm-032.wm:-:*:*:*:*:*:*:* cpe:2.3:o:slican:ipm-032_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:slican:ipu-14.105.wm:-:*:*:*:*:*:*:* cpe:2.3:o:slican:ipu-14_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:slican:ipl-256.3u:-:*:*:*:*:*:*:* cpe:2.3:o:slican:ipl-256_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:slican:ipl-256.wm:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ipu-14.103.wm:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ipu-14.105.1u:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ipm-032.2u:-:*:*:*:*:*:*:* |
|
| First Time |
Slican ncp Server Cm600p.1bc
Slican ipl-256.3u Slican ncp Server Cm400p.1bc Slican ipm-032.wm Slican Slican ipl-256.wm Slican ipu-14 Firmware Slican ipm-032.2u Slican ipu-14.105.1u Slican ipu-14.105.wm Slican ncp Server Cm300p Slican ncp Server Cm300p.1bc Slican ipm-032 Firmware Slican ncp Firmware Slican ipu-14.103.wm Slican ipl-256 Firmware |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | () https://cert.pl/posts/2026/02/CVE-2025-14577 - Third Party Advisory | |
| References | () https://www.slican.pl/oferta/centrale-telefoniczne/ - Product |
24 Feb 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-24 14:16
Updated : 2026-03-02 14:10
NVD link : CVE-2025-14577
Mitre link : CVE-2025-14577
CVE.ORG link : CVE-2025-14577
JSON object : View
Products Affected
CWE
CWE-306
Missing Authentication for Critical Function