Slican NCP/IPL/IPM/IPU devices contain an unauthenticated PHP function injection…
Slican NCP/IPL/IPM/IPU devices contain an unauthenticated PHP function injection vulnerability (CVE-2025-14577) allowing remote code execution; patches available.
CERT Polska disclosed CVE-2025-14577, a critical PHP function injection vulnerability affecting Slican NCP, IPL, IPM, and IPU devices. The vulnerability allows unauthenticated remote attackers to execute arbitrary PHP commands by sending specially crafted requests to the /webcti/session_ajax.php endpoint. No authentication is required to exploit this flaw, making it a high-severity pre-authentication remote code execution vector.
The vulnerability was responsibly disclosed by researcher Dariusz Gońda and coordinated through CERT Polska's disclosure process. Slican has released patches addressing the issue: version 1.24.0190 for NCP devices and version 6.61.0010 for IPL/IPM/IPU devices. Organizations using affected Slican telecommunications equipment should prioritize patching immediately given the unauthenticated nature of the exploit.
This vulnerability represents a significant risk to telecommunications infrastructure, as successful exploitation would grant attackers full control over affected devices, potentially enabling network compromise, traffic interception, or use as a pivot point for further attacks.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/02/CVE-2025-14577
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free