Executive brief
Slican telephone exchanges, which manage corporate voice communications and PBX services, contain a flaw that allows unauthorized individuals to bypass administrative login requirements. By sending a specific command, an attacker can gain full control over the device without needing a password. This could lead to eavesdropping on calls, service disruptions, or unauthorized changes to the organization's telephony infrastructure.
Technical details
A vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) exists in the administrative protocol of several Slican telephone exchange models. The flaw allows a remote, unauthenticated attacker to bypass the authentication mechanism entirely by executing a specific command within the administrative protocol. Successful exploitation grants the attacker full administrative access to the device. While patches are available for modern firmware branches, several legacy models (CCT-1668, MAC-6400, CXS-0424) running version 4.xx or lower are end-of-life and require hardware upgrades to receive security fixes.
Affected products
- Slican NCP below 1.24.0250
- Slican IPx series below 6.61.0040
- Slican CCT-1668 below 6.56.0430; 4.xx and below (EOL)
- Slican MAC-6400 below 6.56.0430; 4.xx and below (EOL)
- Slican CXS-0424 below 6.30.0510; 4.xx and below (EOL)
Timeline
- 2026-05-27: advisory: Initial disclosure by CERT.PL