Description
An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality.
Published: 2026-09-09
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized network access exposing live video and device services
Action: Immediate Vendor Contact
AI Analysis

Impact

The vulnerability allows an attacker to obtain the camera hardware’s hard‑coded Wi-Fi password and use it to join the device’s wireless network. Once connected, the attacker can view the live video feed, access device services, query status interfaces and, for the first generation of the device, modify firmware through the update channel. This results in loss of confidentiality for the video stream and potential disruption of device functionality.

Affected Systems

The affected items are the Softish C6 Ear Camera hardware product and the Softish EarVision Android application. No specific firmware or application version information is provided, so all current installations of these products are considered vulnerable.

Risk and Exploitability

The CVSS base score of 8.7 indicates a high‑severity flaw that primarily threatens network confidentiality and available functionality. The absence of an EPSS score suggests a lack of public exploitation data, but the vulnerability is listed as not part of the CISA KEV catalog. The likely attack path involves any entity that can reach the camera’s Wi-Fi network, either through local network proximity or compromised Wi-Fi infrastructure, enabling the attacker to connect immediately using the exposed password.

Generated by OpenCVE AI on September 9, 2026 at 16:28 UTC.

Remediation

Vendor Solution

The vendor has not responded to requests to work with CISA to mitigate these vulnerabilities. Users are encouraged to reach out directly to the vendor.


OpenCVE Recommended Actions

  • Contact Softish immediately to request a patch or a safe‑mode configuration that removes the hard‑coded credentials
  • Change the camera’s Wi-Fi password and enforce a strong, unique password on the router or access point
  • Restrict or disable the firmware‑update function so that only authenticated management traffic can access it
  • Isolate the camera on a separate VLAN or network segment to limit exposure to other devices
  • Apply any vendor guidelines that mitigate remote access to the video stream and reduce exposed services on the device

Generated by OpenCVE AI on September 9, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Softish
Softish c6 Ear Camera
Softish earvision Android Application
Vendors & Products Softish
Softish c6 Ear Camera
Softish earvision Android Application

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality.
Title Softish C6 Ear Camera and EarVision Android Application Use of Hard-coded Credentials
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Softish C6 Ear Camera Earvision Android Application
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-09T19:12:29.811Z

Reserved: 2026-09-02T22:11:32.690Z

Link: CVE-2026-81640

cve-icon Vulnrichment

Updated: 2026-09-09T19:11:13.793Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T16:17:10.567

Modified: 2026-09-10T15:53:23.707

Link: CVE-2026-81640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:10:11Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials