CVE-2025-14577

Szczegóły podatności CVE.
Aktualizacja: 04.03.2026, 01:54 (CET)
non-KEV CVSS 9.8 EPSS 0.0011 Score 29.47

Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint.


This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).

Źródła

ŹródłoLinkUwagi
NVD (NIST)https://nvd.nist.gov/vuln/detail/CVE-2025-14577Karta CVE w NVD
CISA KEVhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14577Wyszukiwanie CVE w KEV
FIRST EPSShttps://api.first.org/data/v1/epss?cve=CVE-2025-14577API EPSS dla CVE
cvd@cert.plhttps://cert.pl/posts/2026/02/CVE-2025-14577Third Party Advisory
cvd@cert.plhttps://www.slican.pl/oferta/centrale-telefoniczne/Product