← back
CVE-2016-6544

iTrack Easy's getgps data can be modified without authentication

EPSS 3.4%CWE-306
getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be exploited to alter the GPS data of a lost device.
Affected products
iTrack · Easy

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →