Sceawere

Vulnerability Detail

CVE-2026-80276UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Comelit Gateway Unauthenticated Information Disclosure

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
2h ago
Vendor
Comelit Group S.p.A.
Product
1456B Multi-User Gateway
Attack Type
CWE-306 Missing Authentication for Critical Function
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface, sensitive device configuration data - including the Remote Configuration Password - can be read in cleartext by a remote, unauthenticated attacker.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-01T06:17:10.430Z",
  "pubdate": "2026-10-01T06:17:10.430Z",
  "executiveSummary": "The Comelit Multi-User Gateway for VIP System (model 1456B) contains a critical security vulnerability involving an unauthenticated management interface. This flaw allows remote, unauthorized actors to access sensitive system configuration data without requiring valid credentials. The primary impact of this vulnerability is the disclosure of the Remote Configuration Password in cleartext, which facilitates further compromise of the gateway and the broader VIP system infrastructure. The vulnerability is present in firmware versions 2.9.1 and 2.10.0. Given the lack of authentication mechanisms, the attack surface is exposed to any network entity capable of reaching the management interface. This poses a significant risk to the integrity and confidentiality of the device, as an attacker gaining these credentials could potentially achieve full administrative control or conduct further malicious activities within the environment. No specialized access or previous authentication is required to trigger this disclosure, making the exploit highly accessible for potential adversaries.",
  "technicalDetails": "The vulnerability manifests within the web-based management interface of the Comelit Multi-User Gateway (model 1456B). Analysis confirms that the application architecture fails to implement mandatory session management or access control checks for specific API endpoints or configuration pages responsible for serving device metadata. By interacting with these network-accessible interfaces, an unauthorized actor can perform standard HTTP GET requests to retrieve internal configuration parameters.\nThe root cause is a deficiency in the access control logic, which treats requests to sensitive system resources as globally accessible regardless of the sender's identity. The firmware versions 2.9.1 and 2.10.0 exhibit this behavior, effectively bypassing security barriers that would otherwise protect sensitive data. During the exploitation phase, an attacker does not need to submit valid session cookies or authorization headers, as the backend logic does not validate the presence or legitimacy of such credentials.\nThe attack flow follows a straightforward progression: First, the attacker performs network reconnaissance to identify the presence of the Comelit gateway on the target segment. Second, the attacker targets the insecure management interface via its network address. Third, by crafting specific requests to the exposed administrative URI, the attacker forces the system to return a response containing device configuration files, which include the plaintext Remote Configuration Password. Because the password is transmitted in cleartext within the application response body, the attacker gains immediate access to credentials intended only for authorized administrative personnel.\nThis vulnerability is particularly severe because the Remote Configuration Password is a critical piece of security material used to protect administrative functions. With this password, an attacker can authenticate to the device's secondary management interfaces, potentially modifying device behavior, disrupting service, or leveraging the device as a persistent foothold within the local network. The lack of rate limiting or authentication on these specific information-disclosure endpoints facilitates automated data harvesting, meaning an attacker could easily script the retrieval of credentials across multiple devices if they are deployed within an enterprise or public network environment."
}
CVE-2026-80276: Comelit Gateway Unauthenticated Information Disclosure (HIGH Severity, CVSS: 7.5) | Sceawere