# Slican NCP/IPL/IPM/IPU devices contain an unauthenticated PHP function injection…

Published: 2026-02-24 · Severity: critical · Sectors: telecommunications
Canonical: https://vorant.io/reports/9fa9c1ce-13df-4262-9ff0-db5d074c4641/slican-ncp-ipl-ipm-ipu-devices-contain-an-unauthenticated-php-function-injection

> Slican NCP/IPL/IPM/IPU devices contain an unauthenticated PHP function injection vulnerability (CVE-2025-14577) allowing remote code execution; patches available.

CERT Polska disclosed CVE-2025-14577, a critical PHP function injection vulnerability affecting Slican NCP, IPL, IPM, and IPU devices. The vulnerability allows unauthenticated remote attackers to execute arbitrary PHP commands by sending specially crafted requests to the /webcti/session_ajax.php endpoint. No authentication is required to exploit this flaw, making it a high-severity pre-authentication remote code execution vector.

The vulnerability was responsibly disclosed by researcher Dariusz Gońda and coordinated through CERT Polska's disclosure process. Slican has released patches addressing the issue: version 1.24.0190 for NCP devices and version 6.61.0010 for IPL/IPM/IPU devices. Organizations using affected Slican telecommunications equipment should prioritize patching immediately given the unauthenticated nature of the exploit.

This vulnerability represents a significant risk to telecommunications infrastructure, as successful exploitation would grant attackers full control over affected devices, potentially enabling network compromise, traffic interception, or use as a pivot point for further attacks.

## Mentioned in this report

- Vulnerabilities: CVE-2025-14577

Source reporting: https://cert.pl/en/posts/2026/02/CVE-2025-14577

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9fa9c1ce-13df-4262-9ff0-db5d074c4641/slican-ncp-ipl-ipm-ipu-devices-contain-an-unauthenticated-php-function-injection.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
