iTrack Easy's getgps data can be modified without authentication
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 3.4%
exploitation probability
3.4%top 12% of all CVEs
observed exploitation
nono source reports it
getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be exploited to alter the GPS data of a lost device.
Affected products
iTrack · Easy