Three critical authentication bypass vulnerabilities in Slican telephone exchanges allow…
Three critical authentication bypass vulnerabilities in Slican telephone exchanges allow unauthenticated remote attackers to gain full administrative access.
CERT Polska coordinated disclosure of three authentication bypass vulnerabilities affecting Slican telephone exchange systems. CVE-2026-35087 allows attackers to bypass administrative protocol authentication by executing specific commands without credentials. CVE-2026-35089 enables attackers to deduce secure keys through predictable generation based on obtainable exchange properties, leading to admin credential compromise. CVE-2026-35090 permits remote control panel management via telephone connection with a specific caller ID, bypassing authentication entirely and granting full service protocol and configuration access regardless of remote access settings.
Patches are available for current product lines including NCP (v1.24.0250), IPx series (v6.61.0040), CCT-1668 (v6.56.0430), MAC-6400 (v6.56.0430), and CXS-0424 (v6.30.0510). However, end-of-life models running version 4.xx and below, discontinued in 2011-2012, remain vulnerable and require hardware upgrades to receive patches. The vendor recommends affected users contact their service department for upgrade options.
These vulnerabilities pose significant risk to telecommunications infrastructure, as they enable complete administrative takeover without authentication. Organizations using affected Slican systems should prioritize patching or replacement of vulnerable equipment.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-35087
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free