Description
An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior.
Published: 2026-09-09
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to spoof the C6 Ear Camera, effectively positioning themselves as a man‑in‑the‑middle or device emulator. Through this spoofing, the attacker can manipulate the device’s status responses, observe the commands sent by the EarVision Android application, and may even trigger firmware‑update behavior. This provides an attacker with extensive control over the camera’s configuration and the potential to deliver malicious firmware. The weakness is classified as Authentication Bypass (CWE-290).

Affected Systems

Affected products are Softish’s C6 Ear Camera and the Softish EarVision Android application. Version details are not disclosed; all available releases may be vulnerable until the vendor releases a fix or mitigation. The flaw remains present in the current firmware and application as shipped.

Risk and Exploitability

The CVSS base score of 8.4 indicates a high severity vulnerability. Because no CEPS or EPSS score is available and the issue is not listed in CISA’s KEV catalog, the publicly reported exploitation probability is unclear, but the authentication bypass nature of the flaw makes it a potentially high‑impact attack vector. Inferred from the description, the attack likely requires an attacker to be on the same local network or have prior physical proximity to mimic the camera’s identity; the vulnerability can then be leveraged to intercept or modify data exchanged between the camera and the application. The lack of an official vendor patch underscores the risk, as this flaw remains unmitigated.

Generated by OpenCVE AI on September 9, 2026 at 16:29 UTC.

Remediation

Vendor Solution

The vendor has not responded to requests to work with CISA to mitigate these vulnerabilities. Users are encouraged to reach out directly to the vendor.


OpenCVE Recommended Actions

  • Reach out directly to Softish to request a patch or detailed guidance on how to secure the camera and application
  • Implement network segmentation and restrict access to the camera, ensuring that only trusted devices on a secure subnet can communicate with it
  • Monitor network traffic for unexpected camera connections or anomalous status responses, and trigger alerts if spoofed traffic is detected
  • If the application supports it, enforce mutual TLS or certificate pinning so that only a correctly signed camera can be authenticated
  • Consider disabling the EarVision Android application or the camera function until a vendor‑issued fix is available

Generated by OpenCVE AI on September 9, 2026 at 16:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior.
Title Softish C6 Ear Camera and EarVision Android Application Authentication bypass by spoofing
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-09T15:36:46.987Z

Reserved: 2026-09-02T22:11:32.686Z

Link: CVE-2026-82563

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T16:17:11.567

Modified: 2026-09-09T16:17:11.567

Link: CVE-2026-82563

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T16:30:05Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing