Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint.
This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).
References
| Link | Resource |
|---|---|
| https://cert.pl/posts/2026/02/CVE-2025-14577 | Third Party Advisory |
| https://www.slican.pl/oferta/centrale-telefoniczne/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
02 Mar 2026, 14:10
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CPE | cpe:2.3:h:slican:ipu-14.105.1u:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ipm-032.wm:-:*:*:*:*:*:*:* cpe:2.3:o:slican:ncp_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:slican:ipl-256.3u:-:*:*:*:*:*:*:* cpe:2.3:o:slican:ipl-256_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:slican:ipu-14.103.wm:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ncp_server_cm400p.1bc:-:*:*:*:*:*:*:* cpe:2.3:o:slican:ipm-032_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:slican:ipu-14.105.wm:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ncp_server_cm600p.1bc:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ipm-032.2u:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ipl-256.wm:-:*:*:*:*:*:*:* cpe:2.3:o:slican:ipu-14_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:slican:ncp_server_cm300p:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ncp_server_cm300p.1bc:-:*:*:*:*:*:*:* |
|
| References | () https://cert.pl/posts/2026/02/CVE-2025-14577 - Third Party Advisory | |
| References | () https://www.slican.pl/oferta/centrale-telefoniczne/ - Product | |
| First Time |
Slican ipm-032.2u
Slican ncp Server Cm300p.1bc Slican ipu-14 Firmware Slican ipu-14.105.wm Slican ipm-032.wm Slican ncp Server Cm300p Slican ipm-032 Firmware Slican ncp Server Cm600p.1bc Slican ipl-256.3u Slican ncp Server Cm400p.1bc Slican ipl-256.wm Slican ncp Firmware Slican Slican ipu-14.103.wm Slican ipu-14.105.1u Slican ipl-256 Firmware |
24 Feb 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-24 14:16
Updated : 2026-03-02 14:10
NVD link : CVE-2025-14577
Mitre link : CVE-2025-14577
CVE.ORG link : CVE-2025-14577
JSON object : View
Products Affected
slican
- ipl-256_firmware
- ipm-032.wm
- ipl-256.wm
- ncp_server_cm300p.1bc
- ncp_server_cm600p.1bc
- ipu-14.105.wm
- ncp_server_cm400p.1bc
- ipu-14.103.wm
- ipu-14_firmware
- ipm-032_firmware
- ncp_firmware
- ncp_server_cm300p
- ipu-14.105.1u
- ipm-032.2u
- ipl-256.3u
CWE
CWE-306
Missing Authentication for Critical Function
