After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 09 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel. | |
| Title | Softish C6 Ear Camera and EarVision Android Application Missing authentication for critical function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published: 2026-09-09T15:41:54.162Z
Updated: 2026-09-09T19:09:20.744Z
Reserved: 2026-08-21T19:56:57.909Z
Link: CVE-2026-77974
Updated: 2026-09-09T19:09:14.841Z
Status : Received
Published: 2026-09-09T16:17:06.053
Modified: 2026-09-09T20:20:38.513
Link: CVE-2026-77974
No data.