Junglewise Threat Intelligence

CVE-2026-81330: C6 ear camera unencrypted UDP video transmission

CVE-2026-81330 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Vendors: Unknown.

Executive brief

The C6 ear camera transmits live video streams to its companion Android app without encryption over local wireless networks. An attacker within WiFi range can intercept and view the unencrypted video feed, potentially exposing sensitive medical or personal information captured by the camera.

Technical details

The C6 ear camera sends live video frames as JPEG or WEBP images over unencrypted UDP to the EarVision Android application. The application manifest permits cleartext traffic, indicating no transport encryption is enforced. An attacker on the same local network (adjacent network vector) can passively capture UDP packets and reconstruct the video stream without any credentials or authentication. Successful exploitation reveals the live camera feed and could enable man-in-the-middle attacks to inject malicious content or capture credentials. No patch information is currently available in the advisory.

Affected products

  • <UNKNOWN> C6 ear camera <UNKNOWN>
  • <UNKNOWN> EarVision <UNKNOWN>

Timeline

  • 2026-09-09: disclosed: CVE-2026-81330 published

References