<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Kingdom Communication Associated - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/kingdom-communication-associated/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 11 Sep 2026 09:12:31 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/kingdom-communication-associated/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Missing Brute-force Protection in Kingdom Communication Smart Video Intercom</title><link>https://feed.craftedsignal.io/briefs/2026-09-smart-intercom-brute-force/</link><pubDate>Fri, 11 Sep 2026 09:12:31 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-smart-intercom-brute-force/</guid><description>The Kingdom Communication Associated Smart Video Intercom System is vulnerable to credential-based attacks due to the absence of rate limiting or account lockout mechanisms on the authentication interface.</description><content:encoded><![CDATA[<p>The Smart Video Intercom System, developed by Kingdom Communication Associated, contains a critical vulnerability related to missing brute-force protection. This flaw enables unauthenticated remote attackers to perform large-scale login attempts against the device's authentication endpoint. By leveraging the lack of account lockout or rate-limiting thresholds, an attacker can conduct automated credential stuffing or password spraying campaigns to brute-force valid user credentials. Successful exploitation allows unauthorized access to the intercom system, potentially granting attackers control over device functions or access to sensitive communication streams. This vulnerability represents a significant risk for organizations or residential environments deploying these intercoms in network-exposed configurations.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS v3.1 base score of 7.5. Successful exploitation results in complete unauthorized account takeover. Impact includes potential exposure of video/audio feeds, unauthorized control over building entry/access management, and loss of device privacy. The scope of targeting is limited to installations of the Kingdom Communication Associated Smart Video Intercom System exposed to the public internet or accessible via the management network.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of all internet-facing instances of the Kingdom Communication Smart Video Intercom System. Given the absence of native brute-force protection, implement network-level controls immediately.</p>
<ul>
<li>Restrict access to the intercom management interface to authorized IP ranges via firewall or VPN.</li>
<li>Implement monitoring on network gateways for high volumes of HTTP 401 Unauthorized responses or repetitive authentication requests originating from single source IPs.</li>
<li>Contact the vendor, Kingdom Communication Associated, for firmware updates that introduce mandatory account lockout or rate-limiting capabilities.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>