CVE-2026-77974 PUBLISHED

Softish C6 Ear Camera and EarVision Android Application Missing authentication for critical function

Assigner: icscert
Reserved: 21.08.2026 Published: 09.09.2026 Updated: 09.09.2026

After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Softish
Product EarVision Android application
Versions Default: unaffected
  • Version 1.3.1 is affected
Vendor Softish
Product C6 Ear Camera
Versions Default: unaffected
  • Version 1.3.1_Code 132 is affected

Solutions

The vendor has not responded to requests to work with CISA to mitigate these vulnerabilities. Users are encouraged to reach out directly to the vendor.

Credits

  • Matthew Dubbrin from Vexel Foundation reported this vulnerability to CISA finder

References

Problem Types

  • CWE-306 CWE