Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-80275 affects Comelit Multi-User Gateway for VIP System model 1456B running firmware versions 2.9.1 and 2.10.0, exposing a critical authorization bypass in the administrative password-change function. The vulnerability allows any authenticated user—regardless of privilege level—to invoke a function intended only for installers/administrators, enabling them to overwrite the installer account password and gain full system control. This is particularly dangerous in access control and building security systems where the VIP Gateway serves as a central authentication hub. Organizations deploying affected Comelit equipment face immediate risk of unauthorized administrative access, system compromise, and potential physical security breaches across connected entry points.
While this CVE currently shows zero matching Casky skills due to its specificity to Comelit firmware, practitioners using Casky.ai would detect the underlying attack pattern through the platform's authorization and privilege escalation detection capabilities. The vulnerability represents a classic broken access control issue (CWE-425) that Claude AI with extended reasoning can correlate across MITRE ATT&CK techniques including T1548 (Abuse Elevation Control Mechanism), T1078 (Valid Accounts), and T1556 (Modify Authentication Process). When analyzing Comelit VIP Gateway traffic or configuration changes, Casky would flag suspicious password-change requests originating from non-administrative accounts, anomalous credential modification patterns, and unauthorized privilege escalation attempts—surfacing the malicious intent before attackers achieve persistent administrative access to your security infrastructure.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-80275. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation