{"id":"CVE-2026-80276","title":"Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication","summary":"Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface, sensitive device configuration data…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-306"],"vendor":"Comelit Group S.p.A.","product":"1456B Multi-User Gateway","affected":["1456b_multi-user_gateway 2.9.1","1456b_multi-user_gateway 2.10.0"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T13:04:49.340","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80276","references":[{"url":"https://pro.comelitgroup.com/en-us/product/1456B","label":"db4dfee8-a97e-4877-bfae-eba6d14a2166"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-01T06:38:44.649Z","slug":"CVE-2026-80276","body":"## Overview\n\nComelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface, sensitive device configuration data - including the Remote Configuration Password - can be read in cleartext by a remote, unauthenticated attacker.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}