Authentication Bypass Vulnerability in Setracker2 Android Companion App
⚠️ CVE-Referenzen:
CVE-2026-9222
Shenzhen I365-tech Co. Ltd. - Setracker2 Parental Control App (android) Package Com.tgelec.setracker - CRITICAL - CVE-2026-9222.
The Setracker2 Android Companion App has a vulnerability in its authentication mechanism that only requires a password hash for authentication with backend services. As a result, if an attacker obtains this hash, they could successfully authenticate as any user, thereby gaining unauthorized full access to user accounts and sensitive information.
Quelle: securityvulnerability.io