CVE-2026-81330 PUBLISHED

Softish C6 Ear Camera and EarVision Android Application Cleartext transmission of sensitive information

Assigner: icscert
Reserved: 02.09.2026 Published: 09.09.2026 Updated: 09.09.2026

The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor Softish
Product EarVision Android application
Versions Default: unaffected
  • Version 1.3.1 is affected
Vendor Softish
Product C6 Ear Camera
Versions Default: unaffected
  • Version 1.3.1_Code 132 is affected

Solutions

The vendor has not responded to requests to work with CISA to mitigate these vulnerabilities. Users are encouraged to reach out directly to the vendor.

Credits

  • Matthew Dubbrin from Vexel Foundation reported this vulnerability to CISA finder

References

Problem Types

  • CWE-319 CWE