FCC 47 CFR § 11.35(d) — compliance required by September 29, 2026
Station Compliance

Station Compliance›Equipment›Comrex

Equipment note

Comrex codecs ship with the password comrex

Lowercase, documented, and publicly targeted. Comrex has itself urged customers to change it — after becoming aware of a website encouraging attackers to break into Comrex codecs using the manufacturer default.

Verified against manufacturer documentation. Reflects the rule as published August 2026.

Verified. The factory default password on Comrex BRIC-Link devices is comrex, lowercase. Comrex has publicly urged customers to change it, having become aware of a website encouraging attackers to break into Comrex codecs using manufacturer default credentials.

There are two passwords, and only one is the one that matters here

BRIC-Link II and later distinguish two credentials. Stations routinely change one and believe they have changed both.

PasswordWhat it governs
Remote Control Password The web GUI, Device Manager, and firmware updates. This is your management credential — the one 47 CFR § 11.35(d) is chiefly concerned with.
Incoming Connection Password Must accompany incoming connections before they are accepted. Remote units connecting to this codec have to know it.

Both should be strong and distinct. But if you only have ten minutes, change the Remote Control Password first: it is the one that lets someone reconfigure the codec and push firmware to it.

The real problem is usually port 80

Comrex documentation describes TCP port 80 needing to be open or forwarded for remote web GUI access on BRIC-Link III, along with UDP 5060 and the BRIC-Normal port UDP 9000 for certain connection types.

Forwarding port 80 to a codec puts a management interface on the public internet. That is precisely the arrangement the FCC's segmentation requirement exists to end — and a strong password on an internet-facing management GUI is a mitigation, not a solution.

The better arrangement:

Do not simply delete the forward and walk away. Your engineer needs a path in at two in the morning, and an unreachable codec creates its own kind of emergency. Replace the access, don't just remove it.

Check whether it is exposed right now

From a phone on cellular data — not station Wi-Fi — try to reach your public IP address on ports 80, 443, 8080, 22, 23 and 3389. Anything that answers is reachable by the entire internet, and you are looking at exactly what an attacker sees. Do the same for your transmitter site's public IP, which is easy to forget because you rarely think of it as an address you own.

Then verify the password length yourself

We do not publish maximum password lengths where the manufacturer does not document them — a guessed number would cause you to record compliance you do not have. Two minutes on your own unit settles it:

  1. Set a 16-character random password.
  2. Confirm it saves without error.
  3. Log out and log back in with all 16 characters.
  4. Then try only the first 8. If that works, the device is silently truncating — a failure mode that looks exactly like success.

Comrex also publishes a "How to Run a Security Audit" guide, which is worth following alongside your compliance work.

Don't stop at the web password

Most networked broadcast gear exposes more than one management path — web, Telnet, SSH, SNMP, a vendor application, a front panel. They frequently keep separate credential stores, so a strong web password on a unit whose Telnet still takes the factory login has changed nothing except your paperwork.

SNMP deserves particular attention: versions 1 and 2c have no encryption and use community strings as their only credential, and public and private are near-universal defaults. A write-capable SNMP interface is a control path guessed on the first try.

The rest of your rack

Comrex is one entry. The Program Chain Compliance Kit covers verified security behavior for DASDEC, Sage ENDEC, Barix, Tieline, Burk and Inovonics, plus transmitter and audio-over-IP coverage, the credentials that live outside your building, and an eight-step method for anything not listed — with the inventory, port audit and exception templates already written.

See what is in the kit — $149