Comelit Group S.P.A 1456B Multi-User Gateway vulnerabilities
2 known vulnerabilities affecting comelit_group_s.p.a/1456b_multi-user_gateway.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2026-80275P2HIGHCVSS 8.8v2.9.1v2.10.02026-10-01
CVE-2026-80275 [HIGH] CWE-425 CVE-2026-80275: Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to e
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password.
nvd
CVE-2026-80276P3HIGHCVSS 7.5v2.9.1v2.10.02026-10-01
CVE-2026-80276 [HIGH] CWE-306 CVE-2026-80276: Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface, sensitive device configuration data - including the Remote Configuration Password - can be read in cleartext by a remote, unauthenticated attacker.
nvd