CVE-2026-9222 PUBLISHED

Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication

Assigner: icscert
Reserved: 21.05.2026 Published: 25.06.2026 Updated: 26.06.2026

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor Shenzhen i365-Tech Co. Ltd.
Product Setracker2 Parental Control App (Android) package com.tgelec.setracker
Versions Default: unaffected
  • affected from 0 to 3.1.5 (incl.)

Workarounds

The vendor was unresponsive in CISA's attempts to contact for coordination. No known remediations are available. Affected users are encouraged to contact the vendor or their local supplier.

Credits

  • Huancheng Hu of Hasso Plattner Institute reported these vulnerabilities to CISA, with support from Prof. Christian Doerr. finder

References

Problem Types

  • CWE-836 Use of password hash instead of password for authentication CWE