Description
The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption.
Published: 2026-09-09
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to intercept the live video transmitted from the Softish C6 Ear Camera to the EarVision Android application over unencrypted UDP streams. Because the application manifest permits cleartext traffic and the streamed frames are standard JPEG or WEBP images, a local network adversary can capture and reconstruct the video stream in real time, exposing sensitive visual information and potentially personal biometric data.

Affected Systems

Softish products – the C6 Ear Camera and the EarVision Android application – are affected. The issue exists when the camera sends video data to the app over plain UDP, and the app's network security policy allows unencrypted traffic.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability represents moderate‑to‑high severity, primarily compromising confidentiality. The exploitation requires proximity to the local wireless network, which an attacker can achieve by being physically near the device or by compromising a local Wi‑Fi access point. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is local wireless interception. There is no need for privileged system access; the attacker simply listens to the UDP stream.

Generated by OpenCVE AI on September 9, 2026 at 16:30 UTC.

Remediation

Vendor Solution

The vendor has not responded to requests to work with CISA to mitigate these vulnerabilities. Users are encouraged to reach out directly to the vendor.


OpenCVE Recommended Actions

  • Contact Softish to request an encryption fix or to cease transmitting video unencrypted
  • Configure the Android application (or a rooted device) to disallow cleartext traffic by setting android:usesCleartextTraffic="false" or adding a network security configuration that forces TLS or DTLS
  • Block or monitor the UDP port used by the C6 Ear Camera on the local network, and restrict the device to trusted Wi‑Fi or a VPN tunnel

Generated by OpenCVE AI on September 9, 2026 at 16:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption.
Title Softish C6 Ear Camera and EarVision Android Application Cleartext transmission of sensitive information
Weaknesses CWE-319
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-09T15:33:18.094Z

Reserved: 2026-09-02T22:11:32.682Z

Link: CVE-2026-81330

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T16:17:10.397

Modified: 2026-09-09T16:17:10.397

Link: CVE-2026-81330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T16:45:13Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information