Impact
Client‑side authentication bypass in the Kingdom Communication Associated Smart Video Intercom System allows unauthenticated remote attackers to gain access to restricted web pages and pull partial system configuration values. The flaw relies on a weak authentication implementation (CWE-602), providing read‑only visibility into aspects of the intercom firmware such as operational parameters or administrative paths. While the vulnerability does not allow immediate remote code execution, the exposed configuration data can aid attackers in planning subsequent privileged‑access or denial‑of‑service attempts.
Affected Systems
The devices affected are Kingdom Communication Associated models EH1000B, EH2070, EH3040, and EH4200 running firmware versions older than the patched releases (EH3040 pre‑2‑2.5.0A, EH1000B pre‑2.7.0A, EH2070 pre‑2.8.0A).
Risk and Exploitability
The CV and the EPSS score is not available while the vulnerability is not listed in the CISA KEV catalogue, suggesting limited public exploitation activity. Attackers are likely able to reach the susceptible web interfaces over the network using standard HTTP or HTTPS traffic, inferred from the description that the bypass is client‑side. Given the moderate score and absence of known exploits, the risk is moderate, but mitigation is recommended to prevent potential lateral movement or privilege escalation through the exposed configuration data.
OpenCVE Enrichment