Skip to content
Threat Feed
high advisory

Missing Brute-force Protection in Kingdom Communication Smart Video Intercom

The Kingdom Communication Associated Smart Video Intercom System is vulnerable to credential-based attacks due to the absence of rate limiting or account lockout mechanisms on the authentication interface.

CVE search metadata

CVE search record: CVE-2026-89174. Severity: high. CVSS: 7.5. KEV: no. Product: Smart Video Intercom System. Brief: Missing Brute-force Protection in Kingdom Communication Smart Video Intercom. Brief link: https://feed.craftedsignal.io/briefs/2026-09-smart-intercom-brute-force/

The Smart Video Intercom System, developed by Kingdom Communication Associated, contains a critical vulnerability related to missing brute-force protection. This flaw enables unauthenticated remote attackers to perform large-scale login attempts against the device's authentication endpoint. By leveraging the lack of account lockout or rate-limiting thresholds, an attacker can conduct automated credential stuffing or password spraying campaigns to brute-force valid user credentials. Successful exploitation allows unauthorized access to the intercom system, potentially granting attackers control over device functions or access to sensitive communication streams. This vulnerability represents a significant risk for organizations or residential environments deploying these intercoms in network-exposed configurations.

Impact

The vulnerability carries a CVSS v3.1 base score of 7.5. Successful exploitation results in complete unauthorized account takeover. Impact includes potential exposure of video/audio feeds, unauthorized control over building entry/access management, and loss of device privacy. The scope of targeting is limited to installations of the Kingdom Communication Associated Smart Video Intercom System exposed to the public internet or accessible via the management network.

Recommendation

Prioritize the identification of all internet-facing instances of the Kingdom Communication Smart Video Intercom System. Given the absence of native brute-force protection, implement network-level controls immediately.

  • Restrict access to the intercom management interface to authorized IP ranges via firewall or VPN.
  • Implement monitoring on network gateways for high volumes of HTTP 401 Unauthorized responses or repetitive authentication requests originating from single source IPs.
  • Contact the vendor, Kingdom Communication Associated, for firmware updates that introduce mandatory account lockout or rate-limiting capabilities.

Immediate actions

Inventory all Kingdom Communication Smart Video Intercom devices and move them behind a VPN or restricted firewall segment.

IT Operations 24h

Mitigations

Configure network-level rate limiting on the gateway for the intercom management IP addresses.

immediate SOC

CVE-2026-89174