Sceawere

Vulnerability Detail

CVE-2026-80275UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Comelit Gateway Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
Comelit Group S.p.A.
Product
1456B Multi-User Gateway
Attack Type
CWE-425 Direct Request ('Forced Browsing')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-01T06:17:09.720Z",
  "pubdate": "2026-10-01T06:17:09.720Z",
  "executiveSummary": "The Comelit Multi-User Gateway for VIP System (model 1456B) is affected by an improper authorization vulnerability in its administrative password-change function.\nThis vulnerability allows an authenticated user with standard privileges to perform an unauthorized password reset for the installer-level (administrator) account.\nThe issue stems from a failure of the server-side logic to validate the authorization level of the requesting user before executing the password modification request.\nSuccessful exploitation results in full administrative takeover of the gateway, allowing an attacker to modify system settings, intercept communications, or disrupt service availability.\nThe vulnerability affects firmware versions 2.9.1 and 2.10.0. Exploitation requires the attacker to possess valid standard user credentials to initiate the request.\nGiven that the gateway manages communications for the VIP system, the impact of unauthorized administrative access is severe, potentially compromising the integrity and confidentiality of the entire managed environment.",
  "technicalDetails": "The vulnerability is classified as an Improper Authorization flaw, residing within the administrative logic responsible for credential management on the Comelit 1456B gateway.\nIn the affected firmware versions (2.9.1 and 2.10.0), the application fails to perform adequate server-side access control checks on the specific function designated for password updates.\nWhile the interface may visually restrict options for low-privileged users, the underlying function call lacks an enforcement mechanism to verify that the user identity associated with the session holds administrative permissions.\nAn authenticated user can exploit this by crafting a specific HTTP request targeting the password-change function, effectively bypassing the intended privilege constraints.\nThe attack flow proceeds as follows: First, the attacker establishes an authenticated session using their standard user account. Second, the attacker invokes the password modification function by sending a request payload that includes the target 'installer' account identifier and a new desired password.\nBecause the server-side component fails to validate the authorization context of the request, the application processes the input as a legitimate administrative command.\nThe system then overwrites the installer's existing password stored in the backend configuration store with the attacker-provided value.\nOnce the password is changed, the attacker can log in as the installer, gaining complete administrative control over the gateway device.\nPost-exploitation capabilities include the ability to reconfigure system network settings, manipulate device routing, access sensitive logs, or perform further unauthorized actions within the VIP system environment.\nThis vulnerability demonstrates a critical failure in enforcing the Principle of Least Privilege (PoLP) and indicates that security validation relies heavily on client-side interface controls rather than robust, server-side authorization checks.\nThe exposure is limited to authenticated sessions, meaning the attack vector is restricted to users who have already gained access to the network and possesses valid, low-privilege credentials for the device."
}
CVE-2026-80275: Comelit Gateway Privilege Escalation (HIGH Severity, CVSS: 8.8) | Sceawere