CVE-2026-35087 Details
Description
Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter login credentials by executing the appropriate command. This issue was fixed in versions below: - NCP: version 1.24.0250 - IPx series: version 6.61.0040 - CCT-1668: version 6.56.0430 - MAC-6400: version 6.56.0430 - CXS-0424: version 6.30.0510 The issue STILL EXISTS in End-Of-Life telephone exchanges in versions 4.xx and below: - CCT-1668 (CCT1CPU) - MAC-6400 - CXS-0424 These products were discontinued in 2011 and 2012 and and will not receive updates. These products require a hardware update in order to receive a software update. The vendor recommends that users of these devices contact the their service department directly to determine the options for upgrading.
An authentication bypass vulnerability has been identified in the administrative protocol of Slican telephone exchanges. This issue allows attackers to bypass the login requirement by executing a specific command. The vulnerability affects several exchange models, including NCP, IPx series, CCT-1668, MAC-6400, and CXS-0424, all of which are vulnerable in versions prior to the latest updates. Additionally, the vulnerability persists in End-Of-Life exchanges running version 4.xx and below for CCT-1668, MAC-6400, and CXS-0424. These outdated models, discontinued in 2011 and 2012, require a hardware update for a software patch, with the vendor advising users to contact their service department for upgrade options.
Users of the affected Slican telephone exchanges should upgrade to the following versions: NCP: 1.24.0250, IPx series: 6.61.0040, CCT-1668: 6.56.0430, MAC-6400: 6.56.0430, CXS-0424: 6.30.0510. For End-Of-Life models CCT-1668, MAC-6400, and CXS-0424, users should contact the manufacturer's service department to discuss hardware upgrade options.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 27, 2026CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/05/CVE-2026-35087 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Slican NCP | < 1.24.0250 (semver) |
CPE
Remediation
| |
| Slican IPx | < 6.61.0040 (semver) |
CPE
Remediation
| |
| Slican CCT-1668 | < 6.56.0430 (semver) ~4 |
CPE
Remediation
| |
| Slican MAC-6400 | < 6.56.0430 (semver) ~4 |
CPE
Remediation
| |
| Slican CXS-0424 | < 6.30.0510 (semver) ~4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | New CVE Received | [email protected] |
Volerion