Your Comelit Intercom Has Been Hacked — What to Do Next
If you suspect your Comelit intercom or door station has been compromised, act swiftly. Unauthorised access can expose private conversations, enable remote door unlocking, or disrupt your building’s security protocols. The good news is that most breaches are preventable with the right steps. This guide covers brand-specific fixes for Comelit models like the Comelit Icona, Comelit Quadra, and Comelit Visto, ensuring your system is secure and operational.
Quick Fixes to Secure Your Comelit Door Station
Before diving into complex troubleshooting, try these immediate steps to rule out simple causes:
- Power cycle the intercom: For Comelit Visto models, press and hold the pairing button on the back for 10 seconds until the LED flashes. For Comelit Icona or Comelit Quadra, press and hold the reset button on the rear or PCB for 10–15 seconds until the LED flashes rapidly.
- Check the power LED indicator: A solid green light indicates normal operation. If it flickers or is off, verify the PoE switch or 12V DC adapter is functioning correctly.
- Test a call from the app: Open the Comelit App and attempt to call the door station. If the call fails or the video is unresponsive, check your Wi-Fi signal strength or SimpleBus 2-wire connection.
- Verify the door station screen is responsive: If the display freezes or shows error codes, reboot the device or check for firmware updates via the MyComelit portal.
- Confirm the Ethernet/PoE cable is firmly seated: Loose cables can cause intermittent connectivity issues. For Comelit Icona models, ensure the PoE port is properly connected to the switch.
Step 1: Verify SIP Registration and Call Routing
SIP registration failures are a common root cause of intercom breaches. To check your device’s SIP status:
Access the Web Interface
- Open a browser and enter the intercom’s IP address (found in the Device Details section of the MyComelit portal).
- Navigate to Services → SIP and review the Registrar Address, Proxy Settings, and Authentication Credentials.
- Ensure the SIP Status shows Registered. If not, re-enter the SIP details (provided by your network administrator or Comelit support) and restart the device.
For Comelit Quadra Models
If you’re using a Comelit Quadra, confirm the SimpleBus 2-wire or PoE configuration matches the switch settings. If the device is unregistered, re-enter the SIP details and restart the device.
Step 2: Check PoE Power Budget and Wiring
PoE power budget issues can cause instability, leading to unexpected disconnections or reduced performance.
For PoE-Powered Models
- Log into your network switch’s management interface.
- Locate the port connected to your Comelit Icona or Comelit Quadra.
- Verify the PoE Class and Wattage output. Ensure the switch provides at least 12–25W as required by the model.
- If the power budget is exceeded, reconfigure the switch or use a dedicated PoE injector.
For Non-PoE Models
For Comelit Visto models, confirm the 12V DC adapter meets the voltage specifications. Replace any damaged cables or adapters immediately.
Step 3: Configure Door Release Relay and Door Lock Test
A misconfigured relay can allow unauthorised access to doors. To verify your setup:
Use the MyComelit Portal
- Log into the MyComelit management portal and navigate to the Relay and Door Lock Test tool.
- For Comelit Quadra models, ensure the NO/NC/COM wiring matches the relay settings in the Device Configuration section.
- Test the relay manually through the portal. If it fails to trigger, inspect the wiring for shorts or damage.
Step 4: Enable Two-Factor Authentication and Update Firmware
Weak passwords and outdated firmware are major security risks. To mitigate these:
Enable Two-Factor Authentication
- Log into the MyComelit management portal and go to Account Settings.
- Enable two-factor authentication (2FA) via SMS, email, or an authenticator app.
- This ensures only authorised users can access your intercom system.
Update Firmware
- In the MyComelit portal, navigate to the Firmware Upgrade tool.
- Select the appropriate firmware version for your model (e.g. Comelit Icona or Comelit Visto).
- Follow the on-screen prompts to complete the update and restart the device.
Step 5: Review Access Logs and Shared Users
Unauthorised users may have gained access through shared accounts. To check:
Access Logs
- In the MyComelit portal, go to Access Logs and review recent activity for suspicious entries (e.g. login attempts from unknown IP addresses).
- If you notice unauthorised access, change all passwords immediately and disable any shared accounts.
Shared Users
- Navigate to the User Management section in the portal.
- Remove any users who should not have access to your system.
- Ensure all users have strong, unique passwords and 2FA enabled.
Advanced Diagnostics: SIP Server Logs and NAT Traversal
If basic fixes fail, delve deeper into network diagnostics:
Analyse SIP Server Logs
- Contact your SIP provider or network administrator to review server logs for unauthorised access attempts.
- Look for irregularities in SIP registration, proxy settings, or authentication credentials.
NAT Traversal Troubleshooting
- Ensure your router is configured for NAT traversal (STUN, ICE, or ALG settings).
- If remote access fails, enable port forwarding for SIP traffic (typically UDP port) and consult your router’s documentation.
When to Contact Comelit Support
If you’ve exhausted all troubleshooting steps and the issue persists, contact Comelit support via their official portal: https://pro.comelitgroup.com/technical-assistance. Provide details about your model, firmware version, and any error messages encountered.
Understanding the Root Causes of Hacked Comelit Intercoms
Common reasons for breaches include:
- Weak passwords or lack of two-factor authentication
- Outdated firmware with known vulnerabilities
- Unsecured SIP server configurations (e.g. incorrect proxy or registrar settings)
- PoE power budget exhaustion causing device instability
- NAT traversal failures blocking remote access or allowing unauthorised entry
- UK-specific challenges like weather exposure degrading outdoor intercoms or outdated building wiring
Protecting Your Comelit Investment for Your Comelit Intercom
To avoid future breaches, follow these best practices:
- Schedule regular firmware updates via the MyComelit portal
- Renew SIP certificates annually to prevent expiration-related vulnerabilities
- Monitor PoE switch health to avoid power budget exhaustion
- Weatherproof outdoor intercoms with UV-resistant covers and regular cleaning
- Enable 2FA for all user accounts and change passwords every 6 months
Full disclosure: we built scOS to solve persistent connectivity issues with wired camera systems — for intercom-specific problems, the steps above should resolve most issues.
Is It Time for a Comelit Upgrade?: When to Upgrade Your Comelit Intercom
Most Comelit intercoms last 5–8 years with proper maintenance. Replace your device if:
- The intercom shows persistent connectivity issues despite firmware updates
- Physical damage (e.g. cracked housing or water ingress) compromises functionality
- The intercom is over 8 years old and no longer supported by Comelit
Under the UK Consumer Rights Act 2015, you have 6 years (5 in Scotland) to claim faulty goods. If your intercom is under warranty, contact Comelit support for replacement options. For non-warranty devices, consider upgrading to newer models like the Comelit Ultra for enhanced security features.
If troubleshooting takes more than 30 minutes and basic steps (restart/reset/reconnect) haven’t worked, the issue is likely hardware-related. Consult a certified installer or Comelit support for further assistance.