CVE-2026-89175: Kingdom Communication Associated EH1000B
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values.
Affected products
- Kingdom Communication Associated EH1000B: before 2.7.0A (fixed in 2.7.0A)
- Kingdom Communication Associated EH2070: before 2.8.0A (fixed in 2.8.0A)
- Kingdom Communication Associated EH3040: before 2.5.0A (fixed in 2.5.0A)
- Kingdom Communication Associated EH4200: before 2.5.0A (fixed in 2.5.0A)
Published 2026-09-11. Last modified 2026-09-11.