Description
Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values.
Published: 2026-09-11
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side authentication bypass
Action: Apply Patch
AI Analysis

Impact

Client‑side authentication bypass in the Kingdom Communication Associated Smart Video Intercom System allows unauthenticated remote attackers to gain access to restricted web pages and pull partial system configuration values. The flaw relies on a weak authentication implementation (CWE-602), providing read‑only visibility into aspects of the intercom firmware such as operational parameters or administrative paths. While the vulnerability does not allow immediate remote code execution, the exposed configuration data can aid attackers in planning subsequent privileged‑access or denial‑of‑service attempts.

Affected Systems

The devices affected are Kingdom Communication Associated models EH1000B, EH2070, EH3040, and EH4200 running firmware versions older than the patched releases (EH3040 pre‑2‑2.5.0A, EH1000B pre‑2.7.0A, EH2070 pre‑2.8.0A).

Risk and Exploitability

The CV and the EPSS score is not available while the vulnerability is not listed in the CISA KEV catalogue, suggesting limited public exploitation activity. Attackers are likely able to reach the susceptible web interfaces over the network using standard HTTP or HTTPS traffic, inferred from the description that the bypass is client‑side. Given the moderate score and absence of known exploits, the risk is moderate, but mitigation is recommended to prevent potential lateral movement or privilege escalation through the exposed configuration data.

Generated by OpenCVE AI on September 11, 2026 at 09:51 UTC.

Remediation

Vendor Solution

Update EH3040 to version 2.5.0A Update EH4200 to version 2.5.0A Update EH1000B to version 2.7.0A Update EH2070 to version 2.8.0A


OpenCVE Recommended Actions

  • Upgrade EH3040 to firmware version 2.5.0A
  • Upgrade EH4200 to firmware version 2.5.0A
  • Upgrade EH1000B to firmware version 2.7.0A
  • Upgrade EH2070 to firmware version 2.8.0A

Generated by OpenCVE AI on September 11, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values.
Title Kingdom Communication Associated|Smart Video Intercom System - Client-Side Authentication
Weaknesses CWE-602
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-11T07:34:04.092Z

Reserved: 2026-09-11T06:14:47.809Z

Link: CVE-2026-89175

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T08:16:48.543

Modified: 2026-09-11T08:16:48.543

Link: CVE-2026-89175

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:00:09Z

Weaknesses
  • CWE-602

    Client-Side Enforcement of Server-Side Security