Server-Side Authorization Flaw in Comelit Multi-User Gateway for VIP System
CVE-2026-80275

8.8HIGH

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-80275?

The Comelit Multi-User Gateway for VIP System, specifically model 1456B with firmware versions 2.9.1 and 2.10.0, contains a significant flaw that allows authenticated users to change the administrative account password without proper server-side authorization checks. This vulnerability can lead to unauthorized access and compromise the security of the entire system, as it permits users to replace the installer account password and potentially control elevated privileges.

Affected Version(s)

1456B Multi-User Gateway Firmware 2.9.1

1456B Multi-User Gateway Firmware 2.10.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Teemu Tapanila
Juha Jussila
.