Softish has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 7.8 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-81640High· 8.8An attacker could derive the camera's Wi-Fi password and connect to its wireless network48CVE-2026-77974High· 8.0After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.44CVE-2026-82563High· 7.6An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position42CVE-2026-81330Medium· 6.5The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams36
Softish vulnerabilities
CVEs affecting Softish, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-82563High· 7.6An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position
An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of fir…
CVE-2026-81330Medium· 6.5The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams
The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames…
CVE-2026-81640High· 8.8An attacker could derive the camera's Wi-Fi password and connect to its wireless network
An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces…
CVE-2026-77974High· 8.0After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.
After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.