CVE-2026-35090 Details
Description
In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can connect to the modem via a telephone with a specific caller ID. This allows them to bypass admin authentication and gain full access to the service protocol and configuration panel. This vulnerability is independent of the telephone exchanges configuration. If remote access is disabled, calling with this caller ID will temporarily enable it. This issue was fixed in versions below: - IPL-256: version 6.61.0040 - IPM-032: version 6.61.0040 - CCT-1668: version 6.56.0430 - MAC-6400: version 6.56.0430 - CXS-0424: version 6.30.0510 The issue STILL EXISTS in End-Of-Life telephone exchanges in versions 4.xx and below: - CCT-1668 (CCT1CPU) - MAC-6400 - CXS-0424 These products were discontinued in 2011 and 2012 and and will not receive updates. These products require a hardware update in order to receive a software update. The vendor recommends that users of these devices contact the their service department directly to determine the options for upgrading.
An authentication bypass vulnerability has been identified in Slican telephone exchanges, allowing unauthenticated attackers to gain full access to the service protocol and configuration panel. This is achieved by remotely managing the control panel through a telephone call with a specific caller ID, which bypasses admin authentication. The vulnerability exists in several Slican products and versions, and is independent of the telephone exchange's configuration. If remote access is disabled, using the specified caller ID will temporarily enable it.
Users of the affected Slican telephone exchanges should contact their service department directly to discuss options for upgrading, as these products require a hardware update to receive a software update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 27, 2026CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/05/CVE-2026-35087 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Slican IPL-256 | < 6.61.0040 (semver) |
CPE
Remediation
| |
| Slican IPM-032 | < 6.61.0040 (semver) |
CPE
Remediation
| |
| Slican CCT-1668 | < 6.56.0430 (semver) ~4 |
CPE
Remediation
| |
| Slican MAC-6400 | < 6.56.0430 (semver) ~4 |
CPE
Remediation
| |
| Slican CXS-0424 | < 6.30.0510 (semver) ~4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | New CVE Received | [email protected] |
Volerion