CVE-2026-82563 PUBLISHED

Softish C6 Ear Camera and EarVision Android Application Authentication bypass by spoofing

Assigner: icscert
Reserved: 02.09.2026 Published: 09.09.2026 Updated: 09.09.2026

An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor Softish
Product EarVision Android application
Versions Default: unaffected
  • Version 1.3.1 is affected
Vendor Softish
Product C6 Ear Camera
Versions Default: unaffected
  • Version 1.3.1_Code 132 is affected

Solutions

The vendor has not responded to requests to work with CISA to mitigate these vulnerabilities. Users are encouraged to reach out directly to the vendor.

Credits

  • Matthew Dubbrin from Vexel Foundation reported this vulnerability to CISA finder

References

Problem Types

  • CWE-290 CWE