PT-2025-35101 · Meitrack+1 · Meitrack T366G-L+1

Nastycrow

·

Published

2025-08-28

·

Updated

2025-08-28

·

CVE-2025-51643

CVSS v3.1

2.4

Low

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Meitrack T366G-L GPS Tracker devices (affected versions not specified)
Description The SPI flash chip (Winbond 25Q64JVSIQ) in Meitrack T366G-L GPS Tracker devices is accessible without authentication or tamper protection. An attacker with physical access can extract the firmware using a standard SPI programmer, such as flashrom. This allows exposure of sensitive configuration data, including APN credentials, backend server information, and network parameters.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-51643

Affected Products

Meitrack T366G-L
Winbond 25Q64Jvsiq