go to Center block
Upper block

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Kingdom Communication Associated|Smart Video Intercom System - 3 Vulnerabilities

TVN ID TVN-202609004
CVE ID CVE-2026-89173, CVE-2026-89174, CVE-2026-89175
CVSS 【CVE-2026-89173】
6.9 (Medium) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
5.3 (Medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

【CVE-2026-89174】
8.7 (High) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
7.5 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

【CVE-2026-89175】
6.9 (Medium) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
5.3 (Medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products EH3040 before version 2.5.0A
EH4200 before version 2.5.0A
EH1000B before version 2.7.0A
EH2070 before version 2.8.0A
Description 【CVE-2026-89173(Sensitive Data Exposure)】
Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.

【CVE-2026-89174(Missing Burte-force Protection)】
Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.

【CVE-2026-89175(Client-Side Authentication)】
Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values.
Solution Update EH3040 to version 2.5.0A
Update EH4200 to version 2.5.0A
Update EH1000B to version 2.7.0A
Update EH2070 to version 2.8.0A
Credit ASimon、PYu L(AAA Security Technology)
Public Date 2026-09-11
Top