Sceawere

Vulnerability Detail

CVE-2026-89173UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kingdom Communication Intercom Account Enumeration

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
2h ago
Vendor
Kingdom Communication Associated
Product
EH3040
Attack Type
CWE-204 Response Discrepancy Information Exposure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-11T08:16:48.230Z",
  "pubdate": "2026-09-11T08:16:48.230Z",
  "executiveSummary": "The Smart Video Intercom System developed by Kingdom Communication Associated is susceptible to a sensitive data exposure vulnerability resulting from improper validation of authentication responses.\nThis vulnerability manifests as an account enumeration flaw, allowing unauthenticated remote attackers to confirm the existence of valid user accounts within the system.\nBy observing and analyzing discrepancies in server-side responses—such as differing HTTP status codes, specific error messages, or variations in response latency—attackers can systematically verify target identifiers.\nThe primary risk implication is the facilitation of reconnaissance activities, which significantly lowers the barrier for subsequent brute-force, dictionary-based, or credential-stuffing attacks against the identified accounts.\nThis exposure undermines the confidentiality of the user registry and provides adversaries with the necessary intelligence to launch targeted exploitation attempts against specific users, potentially leading to unauthorized system access or further compromise of the intercom infrastructure.\nNo authentication is required to perform these enumeration requests, making the vulnerability particularly accessible to external threats over the network.",
  "technicalDetails": "The vulnerability originates from a failure to implement uniform response patterns during the authentication or user verification process. In secure systems, the response provided to an unauthenticated client should be indistinguishable regardless of whether the submitted user identifier is valid or invalid. In this instance, the Smart Video Intercom System returns distinct indicators that reveal whether a user account exists in the underlying database.\nThe exploitation method relies on side-channel observation of system responses. An attacker performs a series of unauthorized requests against the system's authentication interface or user lookup function using a list of known or guessed usernames.\nThe attack flow is structured as follows: First, the attacker identifies the endpoint responsible for user verification or login. Second, the attacker sends multiple requests with varying usernames. Third, the attacker parses the system responses, specifically monitoring for differences in return codes (e.g., 200 OK vs. 401 Unauthorized), specific error messages (e.g., 'Invalid password' vs. 'User not found'), or fluctuations in packet size and response time. Finally, by correlating these response differences, the attacker effectively filters out invalid usernames and validates existing accounts.\nThe vulnerable component likely resides within the authentication logic or the API backend tasked with handling user session initiation. This vulnerability is network-exposed, allowing any remote actor with access to the system's management or authentication interface to conduct the enumeration without possessing prior credentials or elevated privileges.\nThis behavior facilitates automated scraping of the user directory. Once the attacker establishes a verified list of valid user accounts, the scope of subsequent attacks is refined. Post-exploitation impact includes an increased success rate for password-guessing attacks, as the attacker no longer wastes resources attempting to authenticate against non-existent accounts. This reconnaissance phase is critical for attackers aiming to gain unauthorized entry into the intercom system to perform surveillance, gain remote control of audio/visual feeds, or exploit other downstream vulnerabilities within the device."
}
CVE-2026-89173: Kingdom Communication Intercom Account Enumeration (MEDIUM Severity, CVSS: 5.3) | Sceawere