CRITICAL · 9.8

CVE-2025-14577

Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/s...

Vulnerability Description

Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SlicanNcp Firmware< 1.24.0190
SlicanNcp Server Cm300P-
SlicanNcp Server Cm300P.1Bc-
SlicanNcp Server Cm400P.1Bc-
SlicanNcp Server Cm600P.1Bc-
SlicanIpl-256 Firmware< 6.61.0010
SlicanIpl-256.3U-
SlicanIpl-256.Wm-
SlicanIpm-032 Firmware< 6.61.0010
SlicanIpm-032.2U-
SlicanIpm-032.Wm-
SlicanIpu-14 Firmware< 6.61.0010
SlicanIpu-14.103.Wm-
SlicanIpu-14.105.1U-
SlicanIpu-14.105.Wm-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-14577?

CVE-2025-14577 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/s...

How severe is CVE-2025-14577?

CVE-2025-14577 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2025-14577?

Check the references section above for vendor advisories and patch information. Affected products include: Slican Ncp Firmware, Slican Ncp Server Cm300P, Slican Ncp Server Cm300P.1Bc, Slican Ncp Server Cm400P.1Bc, Slican Ncp Server Cm600P.1Bc.