Unauthorized Firmware Update Vulnerability in Vendor Application
CVE-2026-77974
8.5HIGH
What is CVE-2026-77974?
An attacker may exploit a vulnerability to spoof a device and gain unauthorized user confirmation, allowing the application to transmit firmware through an insecure and unsigned update channel. This poses a significant risk of unauthorized modifications to the device's firmware, which could lead to further exploitation or malfunction.
Affected Version(s)
C6 Ear Camera 1.3.1_Code 132
EarVision Android application 1.3.1
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Matthew Dubbrin from Vexel Foundation reported this vulnerability to CISA
