Executive brief
Slican telephone exchanges, used for managing corporate telephony and communications, contain a security flaw in how they generate encryption keys. An unauthorized person can predict these keys by gathering publicly available information about the device. This allows an attacker to recover administrative credentials, potentially leading to full control over the phone system and its data.
Technical details
The vulnerability is classified as Use of Weak Credentials (CWE-1391). In affected Slican telephone exchanges, the secure key used for administrative access is generated using predictable device-specific properties. These properties can be retrieved by an unauthenticated attacker over the network. By deducing the key from these properties, an attacker can obtain administrative credentials. Patches are available for current models, but legacy hardware (versions 4.xx and below) requires a hardware upgrade to receive software fixes.
Affected products
- Slican IPx series below 6.61.0040
- Slican CCT-1668 below 6.56.0430
- Slican MAC-6400 below 6.56.0430
- Slican CXS-0424 below 6.30.0510
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory