CVE-2026-89174
nicheMissing Brute-Force Protection in Kingdom Communication Smart Video Intercom System
The Smart Video Intercom System developed by Kingdom Communication Associated lacks brute-force protection on its login functionality (CWE-307), allowing unlimited repeated authentication attempts. An unauthenticated remote attacker with network access to the system's login interface can submit a large volume of password guesses to identify and access valid accounts. Successful compromise yields high confidentiality impact per the CVSS 4.0 score (VC:H), meaning the attacker can gain access to account-held information such as intercom access data, though no integrity or availability impact is scored. Any deployment of this intercom system whose management or login interface is reachable over a network is affected, and no fixed version information is provided in the available data. There is currently no known exploitation, no public proof-of-concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Contact Kingdom Communication Associated or check the twcert advisory for a patched firmware release, since no fixed version is specified in the available data. Until patched, restrict the intercom's web/management interface to trusted networks or a VPN rather than exposing it directly to the internet, ensure accounts use long unique passwords to slow offline guessing, and monitor for bursts of failed login attempts. Where feasible, apply rate limiting on the login endpoint (e.g., via a reverse proxy or firewall rules) to compensate for the missing built-in protection.
| Kingdom Communication Associated Smart Video Intercom System | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.
- Weakness
- CWE-307
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.