<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:13:20 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-365899</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-365899</link>
      <description>EUVD-2026-365899</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-365899</guid>
    </item>
    <item>
      <title>fkie_cve-2026-81640</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-81640</link>
      <description>&lt;p&gt;An attacker could derive the camera&amp;#39;s Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker could derive the camera&amp;#39;s Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-81640</guid>
    </item>
    <item>
      <title>GHSA-hpm8-v6q9-rjwv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hpm8-v6q9-rjwv</link>
      <description>&lt;p&gt;An attacker could derive the camera&amp;#39;s Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker could derive the camera&amp;#39;s Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hpm8-v6q9-rjwv</guid>
    </item>
    <item>
      <title>VA-26-251-01 — Softish C6 Ear Camera and EarVision Android Application</title>
      <link>https://cve.radiocsirt.org/vuln/va-26-251-01</link>
      <description>&lt;p&gt;The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption. An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior. An attacker could derive the camera&amp;#39;s Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality. After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption. An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior. An attacker could derive the camera&amp;#39;s Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality. After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/va-26-251-01</guid>
    </item>
  </channel>
</rss>
