Executive brief
Kingdom Communication Associated's Smart Video Intercom System is used for building access control and video communication. An unauthenticated attacker can bypass the system's authentication mechanism to access restricted pages and retrieve partial system configuration information, potentially exposing device settings and enabling further attacks.
Technical details
This is a client-side authentication vulnerability (CVE-2026-89175) in the Smart Video Intercom System where authentication validation is performed only on the client side, allowing unauthenticated remote attackers to bypass it over the network. The vulnerability is network-reachable and requires no authentication or user interaction; attackers can directly access specific pages and extract partial system configuration values. The root cause is the absence of server-side authentication enforcement, enabling direct access to protected resources. Patches are available: update EH3040 and EH4200 to version 2.5.0A, EH1000B to 2.7.0A, and EH2070 to 2.8.0A.
Affected products
- Kingdom Communication Associated Smart Video Intercom System EH3040 before 2.5.0A
- Kingdom Communication Associated Smart Video Intercom System EH4200 before 2.5.0A
- Kingdom Communication Associated Smart Video Intercom System EH1000B before 2.7.0A
- Kingdom Communication Associated Smart Video Intercom System EH2070 before 2.8.0A
Timeline
- 2026-09-11: disclosed