Executive brief
Slican telephone exchanges contain a critical flaw that allows an unauthorized person to take full control of the device. By calling the system's modem using a specific, spoofed caller ID, an attacker can bypass all security checks and access the administrative configuration panel. This can lead to unauthorized monitoring of calls, service disruption, or complete reconfiguration of the organization's phone system.
Technical details
A vulnerability in Slican telephone exchanges (CWE-288) allows for an authentication bypass via an alternate path. An unauthenticated attacker can connect to the device's modem using a specific, hardcoded or predefined caller ID. This action bypasses administrative authentication and grants full access to the service protocol and configuration panel. Notably, the vulnerability is independent of the device configuration; even if remote access is explicitly disabled, a call from the specific caller ID will temporarily enable it. Patches are available for current models, but legacy End-of-Life (EoL) hardware (versions 4.xx and below) requires a hardware upgrade to receive the fix.
Affected products
- Slican IPL-256 below 6.61.0040
- Slican IPM-032 below 6.61.0040
- Slican CCT-1668 below 6.56.0430
- Slican MAC-6400 below 6.56.0430
- Slican CXS-0424 below 6.30.0510
Timeline
- 2026-05-27: advisory: Advisory published by CERT.PL
- 2026-05-27: patched: Fixes released for supported models; EoL models remain vulnerable without hardware upgrades.