CVE-2026-80275: Comelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpoint
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be authenticated to the gateway at a user-level account. No user interaction is required, and the vulnerable password-change function can be reached over the network.
Which systems are known to be affected?
The issue affects Comelit Multi-User Gateway for VIP System model 1456B running firmware versions 2.9.1 or 2.10.0.
What is the impact after successful exploitation?
A low-privilege authenticated user can overwrite the installer account password. This can allow the attacker to take over the administrator-level account and its associated control of the gateway.