Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nastycrow

#53289of 53,630
2.4Total CVSS
Vulnerabilities · 1
PT-2025-35101
2.4
2025-08-28
Meitrack · Meitrack T366G-L · CVE-2025-51643
**Name of the Vulnerable Software and Affected Versions** Meitrack T366G-L GPS Tracker devices (affected versions not specified) **Description** The SPI flash chip (Winbond 25Q64JVSIQ) in Meitrack T366G-L GPS Tracker devices is accessible without authentication or tamper protection. An attacker with physical access can extract the firmware using a standard SPI programmer, such as flashrom. This allows exposure of sensitive configuration data, including APN credentials, backend server information, and network parameters. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.