VYPR

MAC-6400

by Slican

CVEs (2)

  • CVE-2026-35090CriMay 27, 2026
    risk 0.60cvss epss

    In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can connect to the modem via a telephone with a specific caller ID. This allows them to bypass admin authentication and gain full access to the service protocol and…

  • CVE-2026-35089HigMay 27, 2026
    risk 0.57cvss epss

    In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthenticated attacker can deduce the secure key and obtain admin credentials. This issue was fixed in…