Vendors · slican
Products (16)
ipl-256.3u1 CVEsipl-256.wm1 CVEsipl-256 firmware1 CVEsipm-032.2u1 CVEsipm-032.wm1 CVEsipm-032 firmware1 CVEsipu-14.103.wm1 CVEsipu-14.105.1u1 CVEsipu-14.105.wm1 CVEsipu-14 firmware1 CVEsncp firmware1 CVEsncp server cm300p1 CVEsncp server cm300p.1bc1 CVEsncp server cm400p.1bc1 CVEsncp server cm600p.1bc1 CVEswebcti1 CVEs
Recent Vulnerabilities
View all 2 →CVE-2025-14577CRITICAL 9.8
Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).
CVE-2021-45813MEDIUM 6.1
SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's session by injecting malicious JavaScript codes which leads to Session Hijacking and cause user's credentials theft.
