Junglewise Threat Intelligence

CVE-2026-35090: Slican telephone exchanges authentication bypass via specific caller ID

CVE-2026-35090 · Severity: info · CVSS 9.3 · Published 2026-05-27

Technologies: Slican CCT-1668, Slican CXS-0424, Slican MAC-6400. Vendors: Slican.

Executive brief

Slican telephone exchanges contain a critical flaw that allows an unauthorized person to take full control of the device. By calling the system's modem using a specific, spoofed caller ID, an attacker can bypass all security checks and access the administrative configuration panel. This can lead to unauthorized monitoring of calls, service disruption, or complete reconfiguration of the organization's phone system.

Technical details

A vulnerability in Slican telephone exchanges (CWE-288) allows for an authentication bypass via an alternate path. An unauthenticated attacker can connect to the device's modem using a specific, hardcoded or predefined caller ID. This action bypasses administrative authentication and grants full access to the service protocol and configuration panel. Notably, the vulnerability is independent of the device configuration; even if remote access is explicitly disabled, a call from the specific caller ID will temporarily enable it. Patches are available for current models, but legacy End-of-Life (EoL) hardware (versions 4.xx and below) requires a hardware upgrade to receive the fix.

Affected products

  • Slican IPL-256 below 6.61.0040
  • Slican IPM-032 below 6.61.0040
  • Slican CCT-1668 below 6.56.0430
  • Slican MAC-6400 below 6.56.0430
  • Slican CXS-0424 below 6.30.0510

Timeline

  • 2026-05-27: advisory: Advisory published by CERT.PL
  • 2026-05-27: patched: Fixes released for supported models; EoL models remain vulnerable without hardware upgrades.

References

Related threats