PatchSiren

Comelit Group S.p.A. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Comelit Group S.p.A. CVE published 2026-10-01

CVE-2026-80276

CVE-2026-80276 is a high-severity vulnerability in Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0. The vulnerability exposes a network-accessible management interface that does not require authentication, allowing a remote, unauthenticated attacker to read sensitive device configuration data, including the Remote Configuration Password, in cleartext.

HIGH Comelit Group S.p.A. CVE published 2026-10-01

CVE-2026-80275

CVE-2026-80275 debrief based on the supplied source corpus. Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 have a high-severity vulnerability allowing authenticated users to change the installer account password due to insufficient authorization checks. Defenders should prioritize verifying exposure, updating access controls, and monitoring for potential unautho [truncated]