CVE-2026-77974
8.5
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Softish | EarVision Android application | 1.3.1 | affected |
| Softish | C6 Ear Camera | 1.3.1_Code 132 | affected |
Weaknesses
- CWE-306: CWE-306
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.