Slican PBX flaws enable admin auth bypass
Three vulnerabilities in Slican telephone exchange software allow unauthenticated attackers to bypass admin authentication and fully control the devices; some EOL units won't be patched.
CERT Polska coordinated disclosure of three vulnerabilities affecting Slican telephone exchange (PBX) systems, reported by Grupa ŻN. CVE-2026-35087 allows an authentication bypass via a specific administrative command, while CVE-2026-35089 stems from a predictably generated secure key derived from device properties obtainable without authentication, letting an attacker derive admin credentials. The most severe, CVE-2026-35090, permits an unauthenticated attacker to gain full remote control of the device's configuration panel by placing a call to the modem with a specific caller ID — this works even when remote access is disabled, as the call temporarily re-enables it.
The vendor has patched current product lines (NCP, IPx series, CCT-1668, MAC-6400, CXS-0424) in recent firmware versions. However, the CCT-1668, MAC-6400 and CXS-0424 models running firmware 4.xx or earlier — discontinued in 2011-2012 — remain vulnerable and will not receive software updates without a hardware upgrade, leaving legacy deployments permanently exposed unless owners contact the vendor's service department for hardware replacement options.
There is no evidence of active exploitation in the wild; this is a coordinated vulnerability disclosure rather than an observed attack campaign. The risk is nonetheless notable for organizations still operating end-of-life Slican exchanges, as full administrative compromise could enable call interception, toll fraud, or use of the PBX as a pivot point into internal networks.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-35087
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free