CVE-2026-81330

Summary

The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption.

Affected Software

VendorProductVersion RangeStatus
SoftishEarVision Android application1.3.1affected
SoftishC6 Ear Camera1.3.1_Code 132affected

Weaknesses

  • CWE-319: CWE-319

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References