Impact
The vulnerability allows an attacker to obtain the camera hardware’s hard‑coded Wi-Fi password and use it to join the device’s wireless network. Once connected, the attacker can view the live video feed, access device services, query status interfaces and, for the first generation of the device, modify firmware through the update channel. This results in loss of confidentiality for the video stream and potential disruption of device functionality.
Affected Systems
The affected items are the Softish C6 Ear Camera hardware product and the Softish EarVision Android application. No specific firmware or application version information is provided, so all current installations of these products are considered vulnerable.
Risk and Exploitability
The CVSS base score of 8.7 indicates a high‑severity flaw that primarily threatens network confidentiality and available functionality. The absence of an EPSS score suggests a lack of public exploitation data, but the vulnerability is listed as not part of the CISA KEV catalog. The likely attack path involves any entity that can reach the camera’s Wi-Fi network, either through local network proximity or compromised Wi-Fi infrastructure, enabling the attacker to connect immediately using the exposed password.
OpenCVE Enrichment