VORANT. Threat Intelligence Sign in Get the full feed

Slican NCP/IPL/IPM/IPU devices contain an unauthenticated PHP function injection…

critical vulnerability telecommunications

Slican NCP/IPL/IPM/IPU devices contain an unauthenticated PHP function injection vulnerability (CVE-2025-14577) allowing remote code execution; patches available.

CERT Polska disclosed CVE-2025-14577, a critical PHP function injection vulnerability affecting Slican NCP, IPL, IPM, and IPU devices. The vulnerability allows unauthenticated remote attackers to execute arbitrary PHP commands by sending specially crafted requests to the /webcti/session_ajax.php endpoint. No authentication is required to exploit this flaw, making it a high-severity pre-authentication remote code execution vector.

The vulnerability was responsibly disclosed by researcher Dariusz Gońda and coordinated through CERT Polska's disclosure process. Slican has released patches addressing the issue: version 1.24.0190 for NCP devices and version 6.61.0010 for IPL/IPM/IPU devices. Organizations using affected Slican telecommunications equipment should prioritize patching immediately given the unauthenticated nature of the exploit.

This vulnerability represents a significant risk to telecommunications infrastructure, as successful exploitation would grant attackers full control over affected devices, potentially enabling network compromise, traffic interception, or use as a pivot point for further attacks.

Mentioned in this report

Vulnerabilities CVE-2025-14577

Source reporting: https://cert.pl/en/posts/2026/02/CVE-2025-14577

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free