CVE-2026-81330
Deferred Deferred - Pending Action

Live Video Stream Exposure in EarVision Android App

Vulnerability report for CVE-2026-81330, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: ICS-CERT

Description

The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
softish c6_ear_camera *
softish earvision_android_application *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The C6 ear camera sends live video to the EarVision Android app without encryption using UDP streams. The app allows cleartext traffic, and video frames in JPEG or WEBP format are transmitted in plaintext. An attacker within local Wi-Fi range can intercept and reconstruct the live video feed.

Detection Guidance

Detecting this vulnerability requires monitoring for unencrypted UDP video streams from the C6 ear camera. Use network sniffing tools like tcpdump or Wireshark to capture UDP traffic on the local network. Look for JPEG or WEBP video frames transmitted without encryption. Example command: tcpdump -i wlan0 -A udp port 12345 | strings. Check if the EarVision Android app allows cleartext traffic in its manifest.

  • Use tcpdump or Wireshark to capture UDP traffic on the local network interface.
  • Filter for UDP packets containing JPEG or WEBP video frames.
  • Inspect the EarVision Android app manifest for cleartext traffic permissions.
Impact Analysis

An attacker nearby could capture your live video feed from the C6 ear camera without your knowledge. This could expose sensitive or private activities in real time, leading to privacy violations or misuse of the footage.

Compliance Impact

This vulnerability likely violates privacy and data protection regulations such as GDPR and HIPAA, which require secure transmission and protection of personal data. Unencrypted video streams could lead to non-compliance and potential legal consequences.

Mitigation Strategies

Immediately isolate the C6 ear camera and EarVision Android app from untrusted networks. Disable the camera when not in use. Contact the vendor for firmware updates or patches. Avoid using the device in sensitive environments until a fix is available.

  • Isolate the C6 ear camera and EarVision app from untrusted networks.
  • Disable the camera when not actively in use.
  • Contact the vendor for firmware updates or patches.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81330. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart