PT-2026-52634 · Shenzhen I365 Tech Co. · Setracker2 Parental Control App (Android) Package Com.Tgelec.Setracker

Huancheng Hu

·

Publicado

2026-06-25

·

Atualizado

2026-06-26

·

CVE-2026-9219

CVSS v3.1

6.5

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging to other users.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-9219

Produtos afetados

Setracker2 Parental Control App (Android) Package Com.Tgelec.Setracker