CVE-2026-89173
Received Received - Intake

Sensitive Data Exposure in Kingdom Smart Video Intercom System

Vulnerability report for CVE-2026-89173, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: TWCERT/CC

Description

Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
kingdom_communication_associated smart_video_intercom_system 2.5.0A
kingdom_communication_associated smart_video_intercom_system 2.7.0A
kingdom_communication_associated smart_video_intercom_system 2.8.0A

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-204 The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-89173 is a Sensitive Data Exposure vulnerability in Kingdom Communication Associated's Smart Video Intercom System. Unauthenticated remote attackers can exploit differences in system responses to enumerate valid user accounts without needing credentials.

Detection Guidance

To detect CVE-2026-89173, monitor network traffic for unauthenticated account enumeration attempts targeting the Smart Video Intercom System. Check for unusual response patterns or timing differences when querying user accounts. Use tools like Nmap to scan for affected device models (EH3040, EH4200, EH1000B, EH2070) and verify software versions against the patched releases.

Impact Analysis

This vulnerability allows attackers to identify valid accounts on the system, which could lead to further attacks like brute-forcing passwords or accessing sensitive data. It compromises user privacy and system security by exposing account information.

Compliance Impact

This vulnerability may violate data protection regulations like GDPR and HIPAA by exposing sensitive user account information. Organizations using affected systems could face compliance violations, legal penalties, and reputational damage due to unauthorized data exposure.

Mitigation Strategies

Immediately update affected devices to the latest patched versions: EH3040/EH4200 to 2.5.0A or later, EH1000B to 2.7.0A or later, and EH2070 to 2.8.0A or later. If updates are unavailable, isolate the devices from untrusted networks and implement strict access controls to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89173. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart