Unrated severityNVD Advisory· Published Feb 24, 2026· Updated Feb 24, 2026
PHP Function Injection in Slican NPC/IPL/IPM/IPU
CVE-2025-14577
Description
Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint.
This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- cert.pl/posts/2026/02/CVE-2025-14577mitrethird-party-advisory
- www.slican.pl/oferta/centrale-telefoniczne/mitreproduct
News mentions
0No linked articles in our index yet.