Impact
The Smart Video Intercom System, produced by Kingdom Communication Associated, contains a Sensitive Data Exposure flaw that permits unauthenticated remote attackers to discover valid user accounts by exploiting measurable differences in system responses. This vulnerability is identified as CWE-204, signifying that an interface may inadvertently reveal sensitive information. The ability to enumerate accounts can provide attackers with information that could facilitate subsequent credential‑based attacks against the intercom system.
Affected Systems
Affected firmware on Kingdom Communication Associated models EH1000B, EH2070, EH3040, and EH4200 are exposed. Firmware updates—EH1000B 2.7.0A, EH2070 2.8.0A, EH3040 2.5.0A, and EH4200 2.5.0A—source data indicate that applying these revisions removes the enumeration vector.
Risk and Exploitability
The CVSS score of 6.9 rates this vulnerability as moderate severity. EPSS data is unavailable, and the issue is not listed in CISA’s KEV catalog, implying no documented active exploitation. The flaw can be triggered over the network by an unauthenticated remote attacker sending specially crafted requests and observing response variations, where reach is possible.
OpenCVE Enrichment