Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.
Metrics
Affected Vendors & Products
References
History
Thu, 25 Jun 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access. | |
| Title | Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication | |
| Weaknesses | CWE-836 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-06-25T23:29:03.046Z
Reserved: 2026-05-21T17:34:16.235Z
Link: CVE-2026-9222
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T00:30:17Z