Beveiligingsadvies

CVE-2025-14577

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-02-24 13:21:06
Laatst bijgewerkt 2026-02-24 15:00:45
Toegewezen door CERT-PL
CVSS-score 9.3
Status PUBLISHED

Beschrijving

Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).