CVE-2026-77974

Summary

After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.

Affected Software

VendorProductVersion RangeStatus
SoftishEarVision Android application1.3.1affected
SoftishC6 Ear Camera1.3.1_Code 132affected

Weaknesses

  • CWE-306: CWE-306

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References