CVE-2026-9220: fallo de gravedad alta en Shenzhen i365-Tech Co. Ltd.
Setracker2 Children's Smartwatch Ecosystem Use of hard-coded cryptographic key
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.7epss 0.4%
probabilidad de explotación
0.4%top 69% de las CVE
explotación observada
noninguna fuente lo reporta
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 watch traffic.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
Shenzhen i365-Tech Co. Ltd. · Setracker2 Parental Control App (Android) package com.tgelec.setrackerCVEs relacionadas — Shenzhen i365-Tech Co. Ltd.
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-9222CRITICALSetracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authenticationEPSS 0.4%CVE-2026-9219HIGHSetracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or IdentifiersEPSS 0.3%CVE-2026-9221HIGHSetracker2 Children's Smartwatch Ecosystem Use of a Broken or Risky Cryptographic AlgorithmEPSS 0.3%