Description
The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption.
Published: 2026-09-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Breach
Action: Contact Vendor
AI Analysis

Impact

The vulnerability allows an attacker to intercept the live video transmitted from the Softish C6 Ear Camera to the EarVision Android application over unencrypted UDP streams. Because the application manifest permits cleartext traffic and the streamed frames are standard JPEG or WEBP images, a local network adversary can capture and reconstruct the video stream in real time, exposing sensitive visual information and potentially personal biometric data.

Affected Systems

Softish products – the C6 Ear Camera and the EarVision Android application – are affected. The issue exists when the camera sends video data to the app over plain UDP, and the app's network security policy allows unencrypted traffic.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability represents moderate‑to‑high severity, primarily compromising confidentiality. The exploitation requires proximity to the local wireless network, which an attacker can achieve by being physically near the device or by compromising a local Wi‑Fi access point. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is local wireless interception. There is no need for privileged system access; the attacker simply listens to the UDP stream.

Generated by OpenCVE AI on September 9, 2026 at 16:30 UTC.

Remediation

Vendor Solution

The vendor has not responded to requests to work with CISA to mitigate these vulnerabilities. Users are encouraged to reach out directly to the vendor.


OpenCVE Recommended Actions

  • Contact Softish to request an encryption fix or to cease transmitting video unencrypted
  • Configure the Android application (or a rooted device) to disallow cleartext traffic by setting android:usesCleartextTraffic="false" or adding a network security configuration that forces TLS or DTLS
  • Block or monitor the UDP port used by the C6 Ear Camera on the local network, and restrict the device to trusted Wi‑Fi or a VPN tunnel

Generated by OpenCVE AI on September 9, 2026 at 16:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Softish
Softish c6 Ear Camera
Softish earvision Android Application
Vendors & Products Softish
Softish c6 Ear Camera
Softish earvision Android Application

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption.
Title Softish C6 Ear Camera and EarVision Android Application Cleartext transmission of sensitive information
Weaknesses CWE-319
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Softish C6 Ear Camera Earvision Android Application
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-09T19:15:41.581Z

Reserved: 2026-09-02T22:11:32.682Z

Link: CVE-2026-81330

cve-icon Vulnrichment

Updated: 2026-09-09T19:15:30.838Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T16:17:10.397

Modified: 2026-09-10T15:53:23.707

Link: CVE-2026-81330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:10:15Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information