CVE-2026-82563 Details
Description
An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior.
A vulnerability exists in the Softish C6 Ear Camera and the EarVision Android application, both version 1.3.1. This vulnerability allows an attacker to impersonate the camera, positioning themselves as a man-in-the-middle or emulating a device. Such an intrusion could lead to unauthorized manipulation of device status responses, interception of application requests, and potentially trigger firmware update processes. The issue arises from the application's permission for unencrypted network traffic, leaving sensitive interactions exposed to interception by attackers within local wireless range.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 9, 2026CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://raw.githubusercontent.com/cisagov/CSAF/refs/heads/develop/csaf_files/VA/white/2026/va-26-251-01.json | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Softish C6 Ear Camera | v1.3.1 (semver) |
CPE
Remediation
| |
| Softish EarVision Android application | v1.3.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | New CVE Received | [email protected] |
Volerion