CVE-2026-35089: CWE-1391 Use of Weak Credentials in Slican IPx
In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthenticated attacker can deduce the secure key and obtain admin credentials. This issue was fixed in versions below: - IPx series: version 6.61.0040 - CCT-1668: version 6.56.0430 - MAC-6400: version 6.56.0430 - CXS-0424: version 6.30.0510 The issue STILL EXISTS in End-Of-Life telephone exchanges in versions 4.xx and below: - CCT-1668 (CCT1CPU) - MAC-6400 - CXS-0424 These products were discontinued in 2011 and 2012 and and will not receive updates. These products require a hardware update in order to receive a software update. The vendor recommends that users of these devices contact the their service department directly to determine the options for upgrading.
AI Analysis
Technical Summary
CVE-2026-35089 describes a vulnerability in Slican IPx telephone exchanges where the secure key generation process is predictable due to reliance on device properties accessible without authentication. This weakness enables an unauthenticated attacker to deduce the secure key and obtain administrative credentials. The issue has been addressed in versions 6.61.0040 for the IPx series, 6.56.0430 for CCT-1668 and MAC-6400, and 6.30.0510 for CXS-0424. However, end-of-life devices running versions 4.xx and below remain vulnerable and will not receive patches due to hardware and software discontinuation.
Potential Impact
An unauthenticated attacker can deduce the secure key and gain administrative access to affected Slican telephone exchanges. This compromises the confidentiality and integrity of the device, potentially allowing full control over the telephone exchange. The vulnerability has a high CVSS 4.0 score of 8.7, indicating significant risk if exploited. End-of-life devices remain vulnerable without available patches.
Mitigation Recommendations
Fixes are available in the specified updated versions of the affected products. Users should upgrade to these fixed versions to remediate the vulnerability. For end-of-life devices that cannot be updated due to hardware discontinuation, the vendor recommends contacting their service department to explore upgrade options. Patch status is not explicitly stated but implied by version fixes; users should verify with the vendor for current remediation guidance.
CVE-2026-35089: CWE-1391 Use of Weak Credentials in Slican IPx
Description
In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthenticated attacker can deduce the secure key and obtain admin credentials. This issue was fixed in versions below: - IPx series: version 6.61.0040 - CCT-1668: version 6.56.0430 - MAC-6400: version 6.56.0430 - CXS-0424: version 6.30.0510 The issue STILL EXISTS in End-Of-Life telephone exchanges in versions 4.xx and below: - CCT-1668 (CCT1CPU) - MAC-6400 - CXS-0424 These products were discontinued in 2011 and 2012 and and will not receive updates. These products require a hardware update in order to receive a software update. The vendor recommends that users of these devices contact the their service department directly to determine the options for upgrading.
CVSS v4.0
Score 8.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-35089 describes a vulnerability in Slican IPx telephone exchanges where the secure key generation process is predictable due to reliance on device properties accessible without authentication. This weakness enables an unauthenticated attacker to deduce the secure key and obtain administrative credentials. The issue has been addressed in versions 6.61.0040 for the IPx series, 6.56.0430 for CCT-1668 and MAC-6400, and 6.30.0510 for CXS-0424. However, end-of-life devices running versions 4.xx and below remain vulnerable and will not receive patches due to hardware and software discontinuation.
Potential Impact
An unauthenticated attacker can deduce the secure key and gain administrative access to affected Slican telephone exchanges. This compromises the confidentiality and integrity of the device, potentially allowing full control over the telephone exchange. The vulnerability has a high CVSS 4.0 score of 8.7, indicating significant risk if exploited. End-of-life devices remain vulnerable without available patches.
Mitigation Recommendations
Fixes are available in the specified updated versions of the affected products. Users should upgrade to these fixed versions to remediate the vulnerability. For end-of-life devices that cannot be updated due to hardware discontinuation, the vendor recommends contacting their service department to explore upgrade options. Patch status is not explicitly stated but implied by version fixes; users should verify with the vendor for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2026-04-01T11:23:16.118Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a16f9cde29bf47b50c0e68e
Added to database: 05/27/2026, 14:03:57 UTC
Last enriched: 05/27/2026, 14:51:27 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 83
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.