Impact
The vulnerability allows an attacker to intercept the live video transmitted from the Softish C6 Ear Camera to the EarVision Android application over unencrypted UDP streams. Because the application manifest permits cleartext traffic and the streamed frames are standard JPEG or WEBP images, a local network adversary can capture and reconstruct the video stream in real time, exposing sensitive visual information and potentially personal biometric data.
Affected Systems
Softish products – the C6 Ear Camera and the EarVision Android application – are affected. The issue exists when the camera sends video data to the app over plain UDP, and the app's network security policy allows unencrypted traffic.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability represents moderate‑to‑high severity, primarily compromising confidentiality. The exploitation requires proximity to the local wireless network, which an attacker can achieve by being physically near the device or by compromising a local Wi‑Fi access point. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is local wireless interception. There is no need for privileged system access; the attacker simply listens to the UDP stream.
OpenCVE Enrichment