CVE-2025-14577
EUVD-2025-20808824.02.2026, 14:16
Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| slican | ncp_firmware | 𝑥 < 1.24.0190 |
| slican | ipl-256_firmware | 𝑥 < 6.61.0010 |
| slican | ipm-032_firmware | 𝑥 < 6.61.0010 |
| slican | ipu-14_firmware | 𝑥 < 6.61.0010 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration