VYPR
Critical severityNVD Advisory· Published May 27, 2026

CVE-2026-35087

CVE-2026-35087

Description

Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter login credentials by executing the appropriate command.

This issue was fixed in versions below: - NCP: version 1.24.0250 - IPx series: version 6.61.0040 - CCT-1668: version 6.56.0430 - MAC-6400: version 6.56.0430 - CXS-0424: version 6.30.0510

The issue STILL EXISTS in End-Of-Life telephone exchanges in versions 4.xx and below: - CCT-1668 (CCT1CPU) - MAC-6400 - CXS-0424 These products were discontinued in 2011 and 2012 and and will not receive updates. These products require a hardware update in order to receive a software update. The vendor recommends that users of these devices contact the their service department directly to determine the options for upgrading.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Slican telephone exchange administrative protocol authentication bypass allows attackers to gain admin access without credentials.

Vulnerability

Slican telephone exchange models (IPx, CCT-1668, MAC-6400, CXS-0424, NCP) contain an authentication bypass vulnerability in the administrative protocol. An attacker can bypass the login credentials by executing a specific command. Affected versions: all below 6.61.0040 (IPx), below 6.56.0430 (CCT-1668, MAC-6400), below 6.30.0510 (CXS-0424), and below 1.24.0250 (NCP). The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) [1].

Exploitation

An attacker with network access to the telephone exchange's administrative interface can exploit this vulnerability by sending a crafted command that bypasses the authentication process. No prior authentication is required. The exact command is not publicly detailed, but the advisory confirms that executing the appropriate command allows bypassing the login step [1].

Impact

Successful exploitation grants the attacker full administrative privileges on the affected telephone exchange. This can lead to complete compromise of the device, including interception of calls, modification of configurations, denial of service, and potential pivot into the internal network. The impact is critical due to the lack of authentication required [1].

Mitigation

The vendor has released fixed versions: NCP 1.24.0250, IPx 6.61.0040, CCT-1668 6.56.0430, MAC-6400 6.56.0430, and CXS-0424 6.30.0510. Users should update immediately. However, end-of-life models (CCT-1668 with CCT1CPU, MAC-6400, CXS-0424) running versions 4.xx and below are no longer supported and will not receive patches. The vendor recommends contacting their service department for hardware upgrade options [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.