CVE-2026-81330 Details
Description
The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption.
A vulnerability exists in the Softish C6 ear camera and the EarVision Android application, both version 1.3.1, due to the transmission of live video over unencrypted UDP streams. The application allows cleartext traffic, enabling an attacker within local wireless range to intercept and reconstruct the video feed. This lack of transport encryption could also facilitate a man-in-the-middle attack, allowing for the manipulation of device status responses and the observation of application requests.
The vendor has not responded to requests to collaborate on mitigating this vulnerability. Users are encouraged to contact the vendor directly.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 9, 2026CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://raw.githubusercontent.com/cisagov/CSAF/refs/heads/develop/csaf_files/VA/white/2026/va-26-251-01.json | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Softish C6 Ear Camera | CSAFPID-0001 CSAFPID-0002 |
CPE
Remediation
| |
| Softish EarVision | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | New CVE Received | [email protected] |
Volerion