Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-35090

CVE-2026-35090: Slican Telephone Exchanges Auth Bypass

CVE-2026-35090 is an authentication bypass vulnerability in Slican telephone exchanges allowing remote attackers to gain full admin access via caller ID spoofing. This article covers technical details, affected models, and patches.

Published:

CVE-2026-35090 Overview

CVE-2026-35090 is an authentication bypass vulnerability [CWE-288] affecting Slican telephone exchanges. An unauthenticated remote attacker can connect to the modem of a vulnerable exchange by placing a call with a specific caller ID. This action grants full access to the service protocol and configuration panel, bypassing administrator authentication entirely. The vulnerability operates independently of the exchange configuration. If remote access is disabled on the device, calling with the privileged caller ID temporarily re-enables it. The flaw impacts multiple Slican exchange models, including end-of-life products that will not receive software updates.

Critical Impact

Unauthenticated attackers gain full administrative control over Slican telephone exchanges by spoofing a single caller ID value, with no user interaction required.

Affected Products

  • Slican IPL-256 (fixed in 6.61.0040), IPM-032 (fixed in 6.61.0040)
  • Slican CCT-1668 and MAC-6400 (fixed in 6.56.0430), CXS-0424 (fixed in 6.30.0510)
  • End-of-life models CCT-1668 (CCT1CPU), MAC-6400, and CXS-0424 running version 4.xx or below remain vulnerable with no patch available

Discovery Timeline

  • 2026-05-27 - CVE-2026-35090 published to the National Vulnerability Database (NVD)
  • 2026-05-27 - Last updated in NVD database

Technical Details for CVE-2026-35090

Vulnerability Analysis

The vulnerability resides in the remote management interface exposed by Slican telephone exchanges. The device authenticates incoming management sessions based on the caller ID transmitted over the telephone line. When the modem detects a specific hardcoded caller ID, the exchange treats the connection as a trusted administrative session. The attacker then receives unrestricted access to the service protocol and configuration panel without supplying any credentials.

The authentication bypass also overrides the remote access toggle. Administrators who explicitly disable remote management cannot rely on that setting as a control. A call placed with the privileged caller ID re-enables remote access for the duration of the session.

Root Cause

The root cause is improper authentication [CWE-288]. The device treats a caller ID, an attacker-controllable, unauthenticated metadata field, as proof of identity. Caller ID values can be spoofed using standard VoIP gateways and SIP providers. The design therefore grants administrative trust on the basis of data the attacker fully controls.

Attack Vector

An attacker places a telephone call to the modem line of the targeted Slican exchange. The call originates from a source that presents the specific caller ID recognized by the firmware. Once the modem answers, the attacker accesses the service protocol and configuration panel as an administrator. From there, the attacker can modify call routing, intercept or redirect calls, alter system configuration, and pivot into connected infrastructure.

Code-level reproduction details are not published by the vendor. Refer to the CERT Polska Security Advisory for the technical disclosure.

Detection Methods for CVE-2026-35090

Indicators of Compromise

  • Unexpected inbound calls to the modem line of a Slican exchange, particularly from unfamiliar or spoofed caller IDs
  • Administrative configuration changes on the exchange without a corresponding authenticated session in audit logs
  • Remote access becoming active on devices where the feature was explicitly disabled

Detection Strategies

  • Correlate call detail records (CDRs) against configuration change events on the PBX to identify changes that follow modem-line calls
  • Baseline the caller IDs that historically reach the management modem and alert on deviations
  • Monitor service protocol sessions for activity outside of approved maintenance windows or from unauthorized sources

Monitoring Recommendations

  • Forward Slican exchange logs and CDRs into a centralized SIEM or data lake for cross-source correlation
  • Alert on any reactivation of the remote access feature after administrative disablement
  • Track outbound network traffic from the exchange for signs of pivoting or data exfiltration following suspicious calls

How to Mitigate CVE-2026-35090

Immediate Actions Required

  • Upgrade supported devices to the fixed firmware: IPL-256 and IPM-032 to 6.61.0040, CCT-1668 and MAC-6400 to 6.56.0430, CXS-0424 to 6.30.0510
  • Inventory all Slican exchanges and identify any end-of-life CCT-1668 (CCT1CPU), MAC-6400, or CXS-0424 units running version 4.xx or below
  • Contact Slican service department to scope hardware upgrade paths for end-of-life devices that cannot run patched firmware
  • Restrict telephone access to the modem line through carrier-level call filtering and dedicated maintenance numbers

Patch Information

Slican has released fixed firmware for supported models. End-of-life devices in versions 4.xx and below for CCT-1668 (CCT1CPU), MAC-6400, and CXS-0424 will not receive software updates and require a hardware upgrade. Patch and advisory details are published in the CERT Polska Security Advisory.

Workarounds

  • Disconnect the management modem line from the public switched telephone network when remote administration is not actively required
  • Place the exchange behind a call-filtering gateway that drops calls from any caller ID not on an explicit allow list
  • Segment the telephone exchange network from sensitive corporate assets to limit blast radius if the device is compromised
  • Schedule decommissioning of end-of-life hardware that cannot be patched

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.