Impact
The Smart Video Intercom System lacks brute‑force protection, allowing unauthenticated remote attackers to repeatedly attempt login credentials and eventually gain access to valid user accounts. This flaw enables unauthorized users to compromise account confidentiality and control, potentially extending to system control or further lateral movement.
Affected Systems
Kingdom Communication Associated products EH1000B, EH2070, EH3040, and EH4200 are affected. Vulnerable firmware versions include all those released before the vendor‑issued updates (EH3040 < 2.5.0A, EH4200 < 2.5.0A, EH1000B < 2.7.0A, EH2070 < 2.8.0A).
Risk and Exploitability
The vulnerability scores 8.7 on CVSS, indicating high severity. Although the EPSS score is not available, the absence of a KEV listing does not diminish the likelihood that attackers will target exposed login interfaces. Exploitation is achievable over the network, requiring only that the intercom’s web or service interface be reachable, and demand no special credentials or local access.
OpenCVE Enrichment