Slican's vulnerability profile centers on a narrow line of telecommunications and IP-based communication appliances, including IPM and IPU series products and their associated firmware components. The durable signal reflects recurrent application-layer input-handling weaknesses, particularly cross-site scripting vulnerabilities and missing authentication controls in critical functions, typical of web-managed network devices. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Slican over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14577CRITICAL Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted r | Feb 24, 2026 | 9.8 | 30 | NO | NO |
CVE-2021-45813MEDIUM SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's session by injecting malicious JavaScript codes which leads to | Dec 28, 2021 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Slican.
Media articles that mention a CVE ID that affects a product developed by Slican — matched by CVE ID, not by vendor name.