CVE-2026-81640 PUBLISHED

Softish C6 Ear Camera and EarVision Android Application Use of Hard-coded Credentials

Assigner: icscert
Reserved: 02.09.2026 Published: 09.09.2026 Updated: 09.09.2026

An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Softish
Product EarVision Android application
Versions Default: unaffected
  • Version 1.3.1 is affected
Vendor Softish
Product C6 Ear Camera
Versions Default: unaffected
  • Version 1.3.1_Code 132 is affected

Solutions

The vendor has not responded to requests to work with CISA to mitigate these vulnerabilities. Users are encouraged to reach out directly to the vendor.

Credits

  • Matthew Dubbrin from Vexel Foundation reported this vulnerability to CISA finder

References

Problem Types

  • CWE-798 CWE