Unencrypted Video Transmission Vulnerability in C6 Ear Camera by EarVision
CVE-2026-81330
7.1HIGH
What is CVE-2026-81330?
The C6 ear camera has a significant flaw that allows live video feeds to be transmitted unencrypted to the EarVision Android application via UDP streams. This vulnerability arises from the application manifest, which allows cleartext traffic, making it possible for an attacker within local wireless range to intercept and reconstruct the live video stream. Captured network traffic can reveal sensitive imagery in formats such as JPEG or WEBP, posing a severe risk to user privacy.
Affected Version(s)
C6 Ear Camera 1.3.1_Code 132
EarVision Android application 1.3.1
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Matthew Dubbrin from Vexel Foundation reported this vulnerability to CISA
