CVE-2026-89174: Kingdom Communication Associated|Smart Video Intercom System - Missing Burte-force Protection
Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kingdom Communication Associated Smart Video Intercom System EH1000Bto a version that resolves this vulnerability.Fixed in 2.7.0A - Upgrade
Upgrade
Kingdom Communication Associated Smart Video Intercom System EH2070to a version that resolves this vulnerability.Fixed in 2.8.0A - Upgrade
Upgrade
Kingdom Communication Associated Smart Video Intercom System EH3040to a version that resolves this vulnerability.Fixed in 2.5.0A - Upgrade
Upgrade
Kingdom Communication Associated Smart Video Intercom System EH4200to a version that resolves this vulnerability.Fixed in 2.5.0A
Event History
Frequently Asked Questions
Who can exploit this issue?
Unauthenticated remote attackers can exploit it. No prior account access or user interaction is required.
What does an attacker need to do to gain access?
The attacker must make a large number of login attempts to identify valid account credentials. The vulnerability is the absence of brute-force protection on the login process.
What is the potential impact if exploitation succeeds?
An attacker can gain access to valid accounts. The reported severity vector indicates a high confidentiality impact, with no reported integrity or availability impact.