Executive brief
Kingdom Communication Associated's Smart Video Intercom System is an access control device used to manage entry to buildings and facilities. An unauthenticated attacker can repeatedly guess login credentials without rate limiting, allowing them to gain unauthorized access to legitimate user accounts and bypass security controls protecting the intercom system.
Technical details
This vulnerability is a missing brute-force protection flaw affecting the authentication mechanism in the Smart Video Intercom System. Unauthenticated remote attackers can exploit the lack of login attempt rate limiting to perform dictionary or credential-stuffing attacks against valid user accounts. The vulnerability requires network access to the device but no prior authentication or user interaction. Successful exploitation grants an attacker full access to a legitimate account, potentially including system configuration, video/audio streams, and door control functions. Patches are available: update EH3040, EH4200, EH1000B, and EH2070 to versions 2.5.0A, 2.5.0A, 2.7.0A, and 2.8.0A respectively.
Affected products
- Kingdom Communication Associated Smart Video Intercom System EH3040 before 2.5.0A
- Kingdom Communication Associated Smart Video Intercom System EH4200 before 2.5.0A
- Kingdom Communication Associated Smart Video Intercom System EH1000B before 2.7.0A
- Kingdom Communication Associated Smart Video Intercom System EH2070 before 2.8.0A
Timeline
- 2026-09-11: disclosed
- 2026-09-11: patched: Patches released for all affected models: EH3040/EH4200 v2.5.0A, EH1000B v2.7.0A, EH2070 v2.8.0A