Your Comelit Intercom May Have Been Hacked — Here’s What to Do
If your Comelit intercom has been compromised, it could expose sensitive data or allow unauthorized access. Common signs include unexpected calls, altered SIP settings, or login attempts from unfamiliar devices. This guide provides brand-specific steps to secure your system, reset passwords, and prevent future breaches.
Quick Fixes to Try First
Before diving into detailed troubleshooting, try these quick checks:
- Power cycle the intercom: Unplug the power source or disconnect the PoE cable for 30 seconds, then reconnect. This resolves temporary glitches.
- Check the power LED: Ensure the status light is stable and not blinking erratically. A faulty LED could indicate a hardware issue.
- Test a call from the Comelit App: Open the app and try initiating a call. If it fails, the issue may be with the app or network connection.
- Verify the screen/display is responsive: If the intercom screen is unresponsive or frozen, restart the device.
- Check the Ethernet/PoE cable: Ensure the cable is firmly seated in the port and not damaged.
Step 1: Check for Unusual Activity in the MyComelit Portal
Log into the MyComelit management portal using your admin credentials. Navigate to Device Health → Access Logs to review recent login attempts. Look for any unfamiliar IP addresses, devices, or timestamps. If you spot suspicious activity, reset your admin password immediately. For Icona models, press and hold the Reset button on the rear of the panel for 15 seconds. For Quadra models, access the Reset button on the PCB inside the panel (requires removing the faceplate with the security tool) and hold it for 10 seconds.
Step 2: Verify SIP Registration and Settings
SIP misconfigurations can leave your intercom vulnerable. Log into the MyComelit portal and go to Device Settings → SIP Configuration. Check the following:
- Registrar Address: Ensure it matches your SIP server’s IP or domain name.
- Proxy Server: Verify this is correctly set to your SIP proxy server.
- Authentication Credentials: Confirm the username and password match your network setup.
- SIP Status: If it shows 'Unregistered', restart the device or check your VLAN configuration in the Network Diagnostics section. For PoE-powered models, ensure your PoE switch delivers at least 12W (check PoE Power Budget in the portal).
Step 3: Address PoE Power Budget Issues
Insufficient PoE power can cause your intercom to malfunction. Access the MyComelit portal → Network Diagnostics → PoE Status. Confirm your switch port supports 802.3af and delivers the required wattage (12-25W for most models). If the Power Negotiation shows 'Failed', try a different port or upgrade to a PoE++ switch. For hardwired models, check the 12V DC adapter output matches the device's specifications (typically 12V/2A).
Is your door station PoE-powered or separately powered?
- PoE-powered → Check your switch’s PoE budget — the port must deliver at least the wattage your model requires.
- Separately powered → Verify the 12V DC adapter output matches the door station’s power requirements.
Step 4: Test and Configure the Door Release Relay
A faulty door release relay can prevent the lock from opening. Log into the MyComelit portal and navigate to Device Settings → Relay Configuration. Ensure the Relay Type (NO/NC) matches your wiring. Test the relay manually via the Relay and Door Lock Test feature. If the Door Release fails, verify the Relay Trigger Duration is set to 1-3 seconds and the COM/NO/NC terminals are correctly connected. For battery-powered models like the Visto, check the Battery Health section for voltage drops.
Step 5: Analyze SIP Logs for Security Breaches
For advanced troubleshooting, access the SIP Logs section in the MyComelit portal. Look for repeated failed login attempts, unusual SIP messages, or unexpected call routing. If logs indicate a breach, reset your SIP credentials and update your SIP server configuration. For persistent issues, use packet capture diagnostics to monitor network traffic and identify malicious activity.
When Basic Fixes Fail: Factory Reset and Support
If basic steps don’t resolve the issue, consider a factory reset:
- Icona models: Press and hold the Reset button on the rear of the panel for 15 seconds until the front LED flashes rapidly.
- Quadra models: Access the Reset button on the PCB (inside the panel) and hold it for 10 seconds until the status LED flashes.
- Visto models: Press and hold the Pairing button on the back of the doorbell for 10 seconds until the LED flashes rapidly.
After resetting, reconfigure your intercom with updated passwords and SIP settings. If the issue persists, contact Comelit support at https://pro.comelitgroup.com/technical-assistance for further assistance.
Understanding the Root Causes of Hacked Intercoms
Common reasons for Comelit intercom breaches include:
- SIP server configuration issues: Incorrect registrar, proxy, or authentication credentials can leave your system vulnerable.
- PoE power budget exhaustion: Insufficient power delivery can cause unstable behavior, especially in multi-device installations.
- Audio/video codec mismatches: Incompatible codecs between endpoints may lead to unexpected call behavior.
- NAT traversal failures: Blocking remote SIP connections due to improper NAT settings.
- UK-specific challenges: Weather exposure on outdoor door stations or outdated wiring in older buildings.
Prevention and Long-Term Care for Your Comelit Intercom
To avoid future breaches, follow these best practices:
- Schedule firmware updates: Regularly check the MyComelit portal for firmware updates and apply them promptly.
- Monitor SIP certificate renewal: Ensure SIP credentials are up to date and not expired.
- Track PoE switch health: Use the PoE Power Budget feature in the portal to monitor switch performance.
- Weatherproof outdoor units: Inspect and clean Comelit intercoms exposed to weather regularly.
- Full disclosure: We built scOS to solve persistent connectivity issues with wired camera systems — for intercom-specific problems, the steps above should resolve most issues.
When to Replace Your Comelit Intercom
Intercoms typically last 5-8 years, but signs of replacement include:
- Persistent hardware failures: If troubleshooting takes over 30 minutes and basic steps (restart/reset/reconnect) fail, it may be hardware-related.
- Battery degradation: For battery-powered models like the Visto, replace batteries if the intercom loses power frequently.
- UK consumer rights: Under the Consumer Rights Act 2015, UK consumers have up to 6 years to claim faulty goods (5 years in Scotland).
By following these steps, you can secure your Comelit intercom and prevent future breaches. For ongoing support, visit the Comelit technical assistance portal directly.