{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3akingdomcommunicationsmart_video_intercom_system/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kingdomcommunication:smart_video_intercom_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-89174"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Smart Video Intercom System"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Kingdom Communication Associated"],"content_html":"\u003cp\u003eThe Smart Video Intercom System, developed by Kingdom Communication Associated, contains a critical vulnerability related to missing brute-force protection. This flaw enables unauthenticated remote attackers to perform large-scale login attempts against the device's authentication endpoint. By leveraging the lack of account lockout or rate-limiting thresholds, an attacker can conduct automated credential stuffing or password spraying campaigns to brute-force valid user credentials. Successful exploitation allows unauthorized access to the intercom system, potentially granting attackers control over device functions or access to sensitive communication streams. This vulnerability represents a significant risk for organizations or residential environments deploying these intercoms in network-exposed configurations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 7.5. Successful exploitation results in complete unauthorized account takeover. Impact includes potential exposure of video/audio feeds, unauthorized control over building entry/access management, and loss of device privacy. The scope of targeting is limited to installations of the Kingdom Communication Associated Smart Video Intercom System exposed to the public internet or accessible via the management network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of all internet-facing instances of the Kingdom Communication Smart Video Intercom System. Given the absence of native brute-force protection, implement network-level controls immediately.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict access to the intercom management interface to authorized IP ranges via firewall or VPN.\u003c/li\u003e\n\u003cli\u003eImplement monitoring on network gateways for high volumes of HTTP 401 Unauthorized responses or repetitive authentication requests originating from single source IPs.\u003c/li\u003e\n\u003cli\u003eContact the vendor, Kingdom Communication Associated, for firmware updates that introduce mandatory account lockout or rate-limiting capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-11T09:12:31Z","date_published":"2026-09-11T09:12:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-smart-intercom-brute-force/","summary":"The Kingdom Communication Associated Smart Video Intercom System is vulnerable to credential-based attacks due to the absence of rate limiting or account lockout mechanisms on the authentication interface.","title":"Missing Brute-force Protection in Kingdom Communication Smart Video Intercom","url":"https://feed.craftedsignal.io/briefs/2026-09-smart-intercom-brute-force/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:kingdomcommunication:smart_video_intercom_system:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}