CVE-2026-35089 Details
Description
In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthenticated attacker can deduce the secure key and obtain admin credentials. This issue was fixed in versions below: - IPx series: version 6.61.0040 - CCT-1668: version 6.56.0430 - MAC-6400: version 6.56.0430 - CXS-0424: version 6.30.0510 The issue STILL EXISTS in End-Of-Life telephone exchanges in versions 4.xx and below: - CCT-1668 (CCT1CPU) - MAC-6400 - CXS-0424 These products were discontinued in 2011 and 2012 and and will not receive updates. These products require a hardware update in order to receive a software update. The vendor recommends that users of these devices contact the their service department directly to determine the options for upgrading.
A vulnerability exists in Slican telephone exchanges due to the secure key being generated in a predictable manner, based on device properties that can be accessed without authentication. This allows an unauthenticated attacker to deduce the secure key and obtain administrative credentials. The vulnerability affects Slican IPx series exchanges prior to version 6.61.0040, as well as CCT-1668, MAC-6400, and CXS-0424 exchanges, all of which are below their respective version 6.56.0430 or 6.30.0510 thresholds. Additionally, this vulnerability persists in End-Of-Life exchanges running version 4.xx and below, specifically CCT-1668 (CCT1CPU), MAC-6400, and CXS-0424, which were discontinued in 2011 and 2012 and will not receive updates.
Users of the affected Slican telephone exchanges should upgrade to the following versions: IPx series: 6.61.0040, CCT-1668: 6.56.0430, MAC-6400: 6.56.0430, CXS-0424: 6.30.0510. For End-Of-Life exchanges in versions 4.xx and below, a hardware update is required to receive a software update, and users should contact their service department to discuss upgrade options.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 27, 2026CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/05/CVE-2026-35087 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1391 | Use of Weak Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Slican IPx | < 6.61.0040 (semver) |
CPE
Remediation
| |
| Slican CCT-1668 | < 6.56.0430 (semver) <= 4 |
CPE
Remediation
| |
| Slican MAC-6400 | < 6.56.0430 (semver) <= 4 |
CPE
Remediation
| |
| Slican CXS-0424 | < 6.30.0510 (semver) <= 4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | New CVE Received | [email protected] |
Volerion