ZeroHour

CVE-2026-89174

niche

Missing Brute-Force Protection in Kingdom Communication Smart Video Intercom System

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

The Smart Video Intercom System developed by Kingdom Communication Associated lacks brute-force protection on its login functionality (CWE-307), allowing unlimited repeated authentication attempts. An unauthenticated remote attacker with network access to the system's login interface can submit a large volume of password guesses to identify and access valid accounts. Successful compromise yields high confidentiality impact per the CVSS 4.0 score (VC:H), meaning the attacker can gain access to account-held information such as intercom access data, though no integrity or availability impact is scored. Any deployment of this intercom system whose management or login interface is reachable over a network is affected, and no fixed version information is provided in the available data. There is currently no known exploitation, no public proof-of-concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Contact Kingdom Communication Associated or check the twcert advisory for a patched firmware release, since no fixed version is specified in the available data. Until patched, restrict the intercom's web/management interface to trusted networks or a VPN rather than exposing it directly to the internet, ensure accounts use long unique passwords to slow offline guessing, and monitor for bursts of failed login attempts. Where feasible, apply rate limiting on the login endpoint (e.g., via a reverse proxy or firewall rules) to compensate for the missing built-in protection.

Affected
Kingdom Communication Associated Smart Video Intercom System
Estimated exposure
nicheunknown; plausibly no more than tens of thousands of installed units (niche regional product, no public install or scan counts) — No public install counts, market-share figures, or internet-exposure scan data exist for this vendor; the estimate assumes limited scale based on its niche, regionally distributed residential/building intercom deployments, some fraction of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.

Weakness
CWE-307
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.