Description
Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.
Published: 2026-09-11
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized account access via brute‑force login
Action: Immediate Patch
AI Analysis

Impact

The Smart Video Intercom System lacks brute‑force protection, allowing unauthenticated remote attackers to repeatedly attempt login credentials and eventually gain access to valid user accounts. This flaw enables unauthorized users to compromise account confidentiality and control, potentially extending to system control or further lateral movement.

Affected Systems

Kingdom Communication Associated products EH1000B, EH2070, EH3040, and EH4200 are affected. Vulnerable firmware versions include all those released before the vendor‑issued updates (EH3040 < 2.5.0A, EH4200 < 2.5.0A, EH1000B < 2.7.0A, EH2070 < 2.8.0A).

Risk and Exploitability

The vulnerability scores 8.7 on CVSS, indicating high severity. Although the EPSS score is not available, the absence of a KEV listing does not diminish the likelihood that attackers will target exposed login interfaces. Exploitation is achievable over the network, requiring only that the intercom’s web or service interface be reachable, and demand no special credentials or local access.

Generated by OpenCVE AI on September 11, 2026 at 08:22 UTC.

Remediation

Vendor Solution

Update EH3040 to version 2.5.0A Update EH4200 to version 2.5.0A Update EH1000B to version 2.7.0A Update EH2070 to version 2.8.0A


OpenCVE Recommended Actions

  • Upgrade Kingdom Communication Associated EH3040 to firmware version 2.5.0A.
  • Upgrade Kingdom Communication Associated EH4200 to firmware version 2.5.0A.
  • Upgrade Kingdom Communication Associated EH1000B to firmware version 2.7.0A.
  • Upgrade Kingdom Communication Associated EH2070 to firmware version 2.8.0A.

Generated by OpenCVE AI on September 11, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.
Title Kingdom Communication Associated|Smart Video Intercom System - Missing Burte-force Protection
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-11T07:31:15.921Z

Reserved: 2026-09-11T06:14:46.734Z

Link: CVE-2026-89174

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T08:16:48.377

Modified: 2026-09-11T08:16:48.377

Link: CVE-2026-89174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:30:11Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts