VORANT. Threat Intelligence Sign in Get the full feed

Slican PBX flaws enable admin auth bypass

medium vulnerability telecommunications

Three vulnerabilities in Slican telephone exchange software allow unauthenticated attackers to bypass admin authentication and fully control the devices; some EOL units won't be patched.

CERT Polska coordinated disclosure of three vulnerabilities affecting Slican telephone exchange (PBX) systems, reported by Grupa ŻN. CVE-2026-35087 allows an authentication bypass via a specific administrative command, while CVE-2026-35089 stems from a predictably generated secure key derived from device properties obtainable without authentication, letting an attacker derive admin credentials. The most severe, CVE-2026-35090, permits an unauthenticated attacker to gain full remote control of the device's configuration panel by placing a call to the modem with a specific caller ID — this works even when remote access is disabled, as the call temporarily re-enables it.

The vendor has patched current product lines (NCP, IPx series, CCT-1668, MAC-6400, CXS-0424) in recent firmware versions. However, the CCT-1668, MAC-6400 and CXS-0424 models running firmware 4.xx or earlier — discontinued in 2011-2012 — remain vulnerable and will not receive software updates without a hardware upgrade, leaving legacy deployments permanently exposed unless owners contact the vendor's service department for hardware replacement options.

There is no evidence of active exploitation in the wild; this is a coordinated vulnerability disclosure rather than an observed attack campaign. The risk is nonetheless notable for organizations still operating end-of-life Slican exchanges, as full administrative compromise could enable call interception, toll fraud, or use of the PBX as a pivot point into internal networks.

Mentioned in this report

Vulnerabilities CVE-2026-35087CVE-2026-35089CVE-2026-35090

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-35087

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free