CVE-2026-80276: Comelit 1456B gateway exposes remote configuration password via unauthenticated management interface
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface, sensitive device configuration data - including the Remote Configuration Password - can be read in cleartext by a remote, unauthenticated attacker.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to remote exploitation?
Comelit Multi-User Gateway for VIP System devices, model 1456B, running firmware 2.9.1 or 2.10.0 are affected when their network-accessible management interface can be reached by an attacker.
Does an attacker need credentials or user interaction to retrieve the password?
No. The management interface does not require authentication, so a remote attacker can read configuration data, including the Remote Configuration Password, without credentials or user interaction.
What information can be exposed?
Sensitive device configuration data is exposed in cleartext through the management interface. This includes the Remote Configuration Password.