CVE-2026-81330: CWE-319 in Softish EarVision Android application
The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption.
AI Analysis
Technical Summary
The Softish EarVision Android application (version 1.3.1) receives live video streams from the C6 ear camera over unencrypted UDP. The application manifest permits cleartext network traffic, and the transmitted video frames (JPEG or WEBP) can be reconstructed by an attacker who can capture the UDP packets within local wireless range. This vulnerability corresponds to CWE-319 (Cleartext Transmission of Sensitive Information). No official patch or remediation level has been published as of the data provided.
Potential Impact
An attacker within local wireless range can intercept and reconstruct live video streams from the C6 ear camera due to lack of transport encryption. This compromises the confidentiality of the video data transmitted between the camera and the EarVision Android application. There is no indication of privilege or user interaction requirements, increasing the risk of exposure in accessible wireless environments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using the application on untrusted or public wireless networks to reduce the risk of interception. Network-level protections such as using VPNs or secure Wi-Fi configurations may help mitigate exposure.
CVE-2026-81330: CWE-319 in Softish EarVision Android application
Description
The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption.
CVSS v4.0
Score 7.1high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Softish EarVision Android application (version 1.3.1) receives live video streams from the C6 ear camera over unencrypted UDP. The application manifest permits cleartext network traffic, and the transmitted video frames (JPEG or WEBP) can be reconstructed by an attacker who can capture the UDP packets within local wireless range. This vulnerability corresponds to CWE-319 (Cleartext Transmission of Sensitive Information). No official patch or remediation level has been published as of the data provided.
Potential Impact
An attacker within local wireless range can intercept and reconstruct live video streams from the C6 ear camera due to lack of transport encryption. This compromises the confidentiality of the video data transmitted between the camera and the EarVision Android application. There is no indication of privilege or user interaction requirements, increasing the risk of exposure in accessible wireless environments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using the application on untrusted or public wireless networks to reduce the risk of interception. Network-level protections such as using VPNs or secure Wi-Fi configurations may help mitigate exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- icscert
- Date Reserved
- 2026-09-02T22:11:32.682Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa17ebbacd9273b4986eddd
Added to database: 09/09/2026, 15:43:55 UTC
Last enriched: 09/09/2026, 15:52:18 UTC
Last updated: 09/09/2026, 21:25:13 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.