Impact
The vulnerability allows an attacker who has spoofed the device and obtained user confirmation to trigger the application to send firmware updates through an unauthenticated and unsigned channel. This could enable the deployment of malicious firmware onto the Softish C6 Ear Camera or its EarVision Android application, threatening the integrity and confidentiality of device operations. The flaw is a missing authentication weakness, classified as CWE‑306.
Affected Systems
The affected products are Softish C6 Ear Camera and the Softish EarVision Android application. No specific version information is provided, so all current releases of these products are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity vulnerability, but the EPSS score is unavailable and the flaw is not listed in the CISA KEV catalog. Attackers can exploit this weakness by first spoofing the device and then obtaining a user confirmation before initiating the firmware transfer. The exploit requires that the device accept the unauthenticated update channel, which is currently present, making the vulnerability relatively straightforward to exploit once the initial conditions are met. Given the high CVSS and the lack of active mitigation from the vendor, the risk to affected users remains significant until a vendor upgrade is issued.
OpenCVE Enrichment