Missing Brute-force Protection in Kingdom Communication Smart Video Intercom
The Kingdom Communication Associated Smart Video Intercom System is vulnerable to credential-based attacks due to the absence of rate limiting or account lockout mechanisms on the authentication interface.
CVE search metadata
CVE search record: CVE-2026-89174. Severity: high. CVSS: 7.5. KEV: no. Product: Smart Video Intercom System. Brief: Missing Brute-force Protection in Kingdom Communication Smart Video Intercom. Brief link: https://feed.craftedsignal.io/briefs/2026-09-smart-intercom-brute-force/
The Smart Video Intercom System, developed by Kingdom Communication Associated, contains a critical vulnerability related to missing brute-force protection. This flaw enables unauthenticated remote attackers to perform large-scale login attempts against the device's authentication endpoint. By leveraging the lack of account lockout or rate-limiting thresholds, an attacker can conduct automated credential stuffing or password spraying campaigns to brute-force valid user credentials. Successful exploitation allows unauthorized access to the intercom system, potentially granting attackers control over device functions or access to sensitive communication streams. This vulnerability represents a significant risk for organizations or residential environments deploying these intercoms in network-exposed configurations.
Impact
The vulnerability carries a CVSS v3.1 base score of 7.5. Successful exploitation results in complete unauthorized account takeover. Impact includes potential exposure of video/audio feeds, unauthorized control over building entry/access management, and loss of device privacy. The scope of targeting is limited to installations of the Kingdom Communication Associated Smart Video Intercom System exposed to the public internet or accessible via the management network.
Recommendation
Prioritize the identification of all internet-facing instances of the Kingdom Communication Smart Video Intercom System. Given the absence of native brute-force protection, implement network-level controls immediately.
- Restrict access to the intercom management interface to authorized IP ranges via firewall or VPN.
- Implement monitoring on network gateways for high volumes of HTTP 401 Unauthorized responses or repetitive authentication requests originating from single source IPs.
- Contact the vendor, Kingdom Communication Associated, for firmware updates that introduce mandatory account lockout or rate-limiting capabilities.
Immediate actions
Inventory all Kingdom Communication Smart Video Intercom devices and move them behind a VPN or restricted firewall segment.
Mitigations
Configure network-level rate limiting on the gateway for the intercom management IP addresses.
CVE-2026-89174