Description
Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.
Published: 2026-09-11
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User Account Enumeration via Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

The Smart Video Intercom System, produced by Kingdom Communication Associated, contains a Sensitive Data Exposure flaw that permits unauthenticated remote attackers to discover valid user accounts by exploiting measurable differences in system responses. This vulnerability is identified as CWE-204, signifying that an interface may inadvertently reveal sensitive information. The ability to enumerate accounts can provide attackers with information that could facilitate subsequent credential‑based attacks against the intercom system.

Affected Systems

Affected firmware on Kingdom Communication Associated models EH1000B, EH2070, EH3040, and EH4200 are exposed. Firmware updates—EH1000B 2.7.0A, EH2070 2.8.0A, EH3040 2.5.0A, and EH4200 2.5.0A—source data indicate that applying these revisions removes the enumeration vector.

Risk and Exploitability

The CVSS score of 6.9 rates this vulnerability as moderate severity. EPSS data is unavailable, and the issue is not listed in CISA’s KEV catalog, implying no documented active exploitation. The flaw can be triggered over the network by an unauthenticated remote attacker sending specially crafted requests and observing response variations, where reach is possible.

Generated by OpenCVE AI on September 11, 2026 at 08:52 UTC.

Remediation

Vendor Solution

Update EH3040 to version 2.5.0A Update EH4200 to version 2.5.0A Update EH1000B to version 2.7.0A Update EH2070 to version 2.8.0A


OpenCVE Recommended Actions

  • Update EH3040 to version 2.5.0A
  • Update EH4200 to version 2.5.0A
  • Update EH1000B to version 2.7.0A
  • Update EH2070 to version 2.8.0A

Generated by OpenCVE AI on September 11, 2026 at 08:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.
Title Kingdom Communication Associated|Smart Video Intercom System - Sensitive Data Exposure
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-11T07:27:52.216Z

Reserved: 2026-09-11T06:14:45.642Z

Link: CVE-2026-89173

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T08:16:48.230

Modified: 2026-09-11T08:16:48.230

Link: CVE-2026-89173

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:00:11Z

Weaknesses
  • CWE-204

    Observable Response Discrepancy