# Slican PBX flaws enable admin auth bypass

Published: 2026-05-27 · Severity: medium · Sectors: telecommunications
Canonical: https://vorant.io/reports/f7cf538b-eb06-59a1-b1a0-279ec13b03bb/slican-pbx-flaws-enable-admin-auth-bypass

> Three vulnerabilities in Slican telephone exchange software allow unauthenticated attackers to bypass admin authentication and fully control the devices; some EOL units won't be patched.

CERT Polska coordinated disclosure of three vulnerabilities affecting Slican telephone exchange (PBX) systems, reported by Grupa ŻN. CVE-2026-35087 allows an authentication bypass via a specific administrative command, while CVE-2026-35089 stems from a predictably generated secure key derived from device properties obtainable without authentication, letting an attacker derive admin credentials. The most severe, CVE-2026-35090, permits an unauthenticated attacker to gain full remote control of the device's configuration panel by placing a call to the modem with a specific caller ID — this works even when remote access is disabled, as the call temporarily re-enables it.

The vendor has patched current product lines (NCP, IPx series, CCT-1668, MAC-6400, CXS-0424) in recent firmware versions. However, the CCT-1668, MAC-6400 and CXS-0424 models running firmware 4.xx or earlier — discontinued in 2011-2012 — remain vulnerable and will not receive software updates without a hardware upgrade, leaving legacy deployments permanently exposed unless owners contact the vendor's service department for hardware replacement options.

There is no evidence of active exploitation in the wild; this is a coordinated vulnerability disclosure rather than an observed attack campaign. The risk is nonetheless notable for organizations still operating end-of-life Slican exchanges, as full administrative compromise could enable call interception, toll fraud, or use of the PBX as a pivot point into internal networks.

## Mentioned in this report

- Vulnerabilities: CVE-2026-35087, CVE-2026-35089, CVE-2026-35090

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-35087

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f7cf538b-eb06-59a1-b1a0-279ec13b03bb/slican-pbx-flaws-enable-admin-auth-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
