CVE-2026-89175
Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.32%
- CWE
- CWE-602
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- Kingdom Communication Associated EH3040
- Kingdom Communication Associated EH4200
- Kingdom Communication Associated EH1000B
- Kingdom Communication Associated EH2070
Weakness type
Related vulnerabilities
- CVE-2026-23478 — Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback
- CVE-2025-33025 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2025-33024 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2025-32469 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2020-24683 — Authentication Bypass in Symphony Plus
- CVE-2023-0750 — Yellowbrik PEC-1864 authentication bypass
- CVE-2022-20658 — Cisco Unified Contact Center Management Portal and Unified Contact Center Domain Manager Privilege Escalation Vulnerability
- CVE-2022-1525 — Cognex 3D-A1000 Dimensioning System Client-Side Enforcement of Server-Side Security