CVE-2026-80275 PUBLISHED

Comelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpoint

Assigner: NCSC-FI
Reserved: 26.08.2026 Published: 01.10.2026 Updated: 01.10.2026

Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor Comelit Group S.p.A.
Product 1456B Multi-User Gateway
Versions Default: unknown
  • Version 2.9.1 is affected
  • Version 2.10.0 is affected

Workarounds

The vendor does not consider this a defect and has stated it will not be fixed, so the device's built-in role separation cannot be relied upon. As a mitigation, treat every account on the device as an administrator-equivalent account. Additionally, restrict network access to the device management interface to trusted administrators only.

Credits

  • Teemu Tapanila finder
  • Juha Jussila finder

References

Problem Types

  • CWE-425 Direct Request ('Forced Browsing') CWE

Impacts

  • CAPEC-87 Forceful Browsing