CVE-2026-81640
Softish · EarVision Android application
A hardcoded credential vulnerability in the Softish EarVision Android application and C6 Ear Camera allows attackers to derive Wi-Fi passwords and gain unauthorized access to the device network.
Executive summary
The Softish EarVision Android application and C6 Ear Camera contain a hardcoded credential vulnerability that permits unauthorized network access and potential exposure of sensitive video streams.
Vulnerability
This vulnerability (CWE-798) involves the use of hardcoded credentials, which allows an attacker to derive the camera Wi-Fi password. This flaw is exploitable by an unauthenticated attacker with adjacent network access.
Business impact
The CVSS score of 8.8 reflects the high risk posed by this vulnerability. Successful exploitation could lead to full compromise of the device, resulting in unauthorized access to live video feeds, device services, and firmware update mechanisms, which may facilitate further attacks on the local network or lead to severe privacy breaches for users.
Remediation
Immediate Action: As the vendor has not yet responded to requests for mitigation, users are encouraged to contact Softish directly to demand a security update and to isolate affected cameras on restricted network segments.
Proactive Monitoring: Monitor network traffic for unauthorized connection attempts to the camera and review device logs for anomalous access patterns.
Compensating Controls: Place the affected cameras on a dedicated, isolated VLAN with no access to internal corporate or home network resources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical nature of this flaw and the lack of a vendor-provided patch, immediate network isolation is required to prevent unauthorized access. Organizations should prioritize replacing these devices if the vendor fails to provide a timely security update.
History
- Collected by CVE Brief via github
- Held for re-check analysis graded thin
- Analyst report written
- Analyst report updated
Sources
Originally found and disclosed by Matthew Dubbrin from Vexel Foundation reported this vulnerability to CISA, per the CVE Program record.