Description
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password.
Published: 2026-10-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

The vendor does not consider this a defect and has stated it will not be fixed, so the device's built-in role separation cannot be relied upon. As a mitigation, treat every account on the device as an administrator-equivalent account. Additionally, restrict network access to the device management interface to trusted administrators only.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:00:00 +0000

Type Values Removed Values Added
Description Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password.
Title Comelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpoint
Weaknesses CWE-425
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC-FI

Published:

Updated: 2026-10-01T05:51:37.479Z

Reserved: 2026-08-26T07:24:58.118Z

Link: CVE-2026-80275

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T06:17:09.720

Modified: 2026-10-01T06:17:09.720

Link: CVE-2026-80275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')