CVE-2026-82563
An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.4
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
- CWE
- CWE-290
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- Softish EarVision Android application
- Softish C6 Ear Camera
Weakness type
Related vulnerabilities
- CVE-2026-88011 — Traefik: ForwardAuth identity spoofing via dot-form header alias
- CVE-2026-66674 — WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Captcha Bypass vulnerability
- CVE-2026-88879 — Traefik before v2.11.56 Identity Spoofing via Header Alias
- CVE-2026-82530 — IP2Location Country Blocker < 2.45.0 Access Control Bypass via X-Real-IP Header
- CVE-2026-62759 — Windows Netlogon Spoofing Vulnerability
- CVE-2026-86478 — In JetBrains YouTrack before 2025.3.161254,...
- CVE-2026-84186 — Incorrect access control in PrestaShop
- CVE-2026-86196 — Grav API Plugin before 1.0.20 Authentication Bypass via Host Header