CVE-2026-89175: Kingdom Communication Associated|Smart Video Intercom System - Client-Side Authentication
Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kingdom Communication Associated Smart Video Intercom System EH1000Bto a version that resolves this vulnerability.Fixed in 2.7.0A - Upgrade
Upgrade
Kingdom Communication Associated Smart Video Intercom System EH2070to a version that resolves this vulnerability.Fixed in 2.8.0A - Upgrade
Upgrade
Kingdom Communication Associated Smart Video Intercom System EH3040to a version that resolves this vulnerability.Fixed in 2.5.0A - Upgrade
Upgrade
Kingdom Communication Associated Smart Video Intercom System EH4200to a version that resolves this vulnerability.Fixed in 2.5.0A
Event History
Frequently Asked Questions
Who can exploit this issue?
Unauthenticated remote attackers can exploit it over the network. No privileges or user interaction are required.
What access could an attacker gain?
An attacker can bypass authentication for specific pages and obtain partial system configuration values. The provided information does not indicate modification of settings or service disruption.