This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 02 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Slican ipl-256.3u
Slican ipl-256.wm Slican ipl-256 Firmware Slican ipm-032.2u Slican ipm-032.wm Slican ipm-032 Firmware Slican ipu-14.103.wm Slican ipu-14.105.1u Slican ipu-14.105.wm Slican ipu-14 Firmware Slican ncp Firmware Slican ncp Server Cm300p Slican ncp Server Cm300p.1bc Slican ncp Server Cm400p.1bc Slican ncp Server Cm600p.1bc |
|
| CPEs | cpe:2.3:h:slican:ipl-256.3u:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ipl-256.wm:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ipm-032.2u:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ipm-032.wm:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ipu-14.103.wm:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ipu-14.105.1u:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ipu-14.105.wm:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ncp_server_cm300p.1bc:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ncp_server_cm300p:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ncp_server_cm400p.1bc:-:*:*:*:*:*:*:* cpe:2.3:h:slican:ncp_server_cm600p.1bc:-:*:*:*:*:*:*:* cpe:2.3:o:slican:ipl-256_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:slican:ipm-032_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:slican:ipu-14_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:slican:ncp_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Slican ipl-256.3u
Slican ipl-256.wm Slican ipl-256 Firmware Slican ipm-032.2u Slican ipm-032.wm Slican ipm-032 Firmware Slican ipu-14.103.wm Slican ipu-14.105.1u Slican ipu-14.105.wm Slican ipu-14 Firmware Slican ncp Firmware Slican ncp Server Cm300p Slican ncp Server Cm300p.1bc Slican ncp Server Cm400p.1bc Slican ncp Server Cm600p.1bc |
|
| Metrics |
cvssV3_1
|
Wed, 25 Feb 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Slican
Slican ipl Slican ipm Slican ipu Slican ncp |
|
| Vendors & Products |
Slican
Slican ipl Slican ipm Slican ipu Slican ncp |
Tue, 24 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Feb 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU). | |
| Title | PHP Function Injection in Slican NPC/IPL/IPM/IPU | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-02-24T15:00:45.355Z
Reserved: 2025-12-12T13:28:43.671Z
Link: CVE-2025-14577
Updated: 2026-02-24T15:00:34.176Z
Status : Analyzed
Published: 2026-02-24T14:16:21.333
Modified: 2026-03-02T14:10:29.920
Link: CVE-2025-14577
No data.
OpenCVE Enrichment
Updated: 2026-02-25T11:39:51Z