CVE-2025-14577: Slican Ipl-256 Firmware

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).

Affected products

  • Slican Ipl-256 Firmware: before 6.61.0010 (fixed in 6.61.0010)
  • Slican Ipm-032 Firmware: before 6.61.0010 (fixed in 6.61.0010)
  • Slican Ipu-14 Firmware: before 6.61.0010 (fixed in 6.61.0010)
  • Slican Ncp Firmware: before 1.24.0190 (fixed in 1.24.0190)

Published 2026-02-24. Last modified 2026-06-17.