Impact
The vulnerability allows an attacker to spoof the C6 Ear Camera, effectively positioning themselves as a man‑in‑the‑middle or device emulator. Through this spoofing, the attacker can manipulate the device’s status responses, observe the commands sent by the EarVision Android application, and may even trigger firmware‑update behavior. This provides an attacker with extensive control over the camera’s configuration and the potential to deliver malicious firmware. The weakness is classified as Authentication Bypass (CWE-290).
Affected Systems
Affected products are Softish’s C6 Ear Camera and the Softish EarVision Android application. Version details are not disclosed; all available releases may be vulnerable until the vendor releases a fix or mitigation. The flaw remains present in the current firmware and application as shipped.
Risk and Exploitability
The CVSS base score of 8.4 indicates a high severity vulnerability. Because no CEPS or EPSS score is available and the issue is not listed in CISA’s KEV catalog, the publicly reported exploitation probability is unclear, but the authentication bypass nature of the flaw makes it a potentially high‑impact attack vector. Inferred from the description, the attack likely requires an attacker to be on the same local network or have prior physical proximity to mimic the camera’s identity; the vulnerability can then be leveraged to intercept or modify data exchanged between the camera and the application. The lack of an official vendor patch underscores the risk, as this flaw remains unmitigated.
OpenCVE Enrichment