Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vendor has not responded to requests to work with CISA to mitigate these vulnerabilities. Users are encouraged to reach out directly to the vendor.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel. | |
| Title | Softish C6 Ear Camera and EarVision Android Application Missing authentication for critical function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-09T15:41:54.162Z
Reserved: 2026-08-21T19:56:57.909Z
Link: CVE-2026-77974
No data.
Status : Received
Published: 2026-09-09T16:17:06.053
Modified: 2026-09-09T16:17:06.053
Link: CVE-2026-77974
No data.
OpenCVE Enrichment
No data.
-
CWE-306
Missing Authentication for Critical Function