ZeroHour

CVE-2026-81330

Cleartext UDP Video Streaming in C6 Ear Camera and EarVision Android App

CVSS 4.0
7.1 high
EPSS
<1%p0
Published
()
Modified
AI analysis

The C6 ear camera sends its live video feed to the EarVision Android application as unencrypted JPEG or WEBP frames over UDP, with the app's manifest explicitly permitting cleartext traffic (CWE-319, Cleartext Transmission of Sensitive Information). Triggering the flaw requires no authentication or user interaction: any attacker within local wireless range, such as someone on the same Wi-Fi network, can passively capture the UDP packets. The captured packets can be reassembled into a live view of the video stream, exposing whatever the camera is pointed at, including potentially sensitive ear-canal imagery, without any transport encryption. Affected users are owners of the C6 ear camera who stream to the EarVision Android app, and the confidentiality-only impact (no integrity or availability effects) earned a CVSS 4.0 score of 7.1 (High). There are no reports of exploitation, no known public proof-of-concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: No patched version numbers are published yet, so check the CISA ICS advisory and the app store listing for an updated EarVision release that encrypts the video transport. Until a fix is available, use the camera only on trusted private Wi-Fi networks and avoid streaming on shared or public wireless networks where others may be within capture range. Monitor vendor communications for a firmware or app update that adds encrypted transport (e.g., DTLS/TLS) and apply it promptly.

Affected
C6 ear camera
EarVision Android application
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption.

Weakness
CWE-319
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.