CVE-2025-14577

EUVD-2025-208088
Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint.


This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
slicanncp_firmware
𝑥
< 1.24.0190
slicanipl-256_firmware
𝑥
< 6.61.0010
slicanipm-032_firmware
𝑥
< 6.61.0010
slicanipu-14_firmware
𝑥
< 6.61.0010
𝑥
= Vulnerable software versions