Junglewise Threat Intelligence

CVE-2026-9219: Shenzhen i365-Tech Setracker2 predictable registration ID in Android app

CVE-2026-9219 · Severity: medium · CVSS 6.5 · Published 2026-06-26

Executive brief

The Setracker2 Android app, used by parents to manage children's smartwatches, uses a predictable identification system for device registration. An attacker who determines a device's registration ID can take control of watches belonging to other users. This could allow unauthorized access to a child's location or communication features, compromising privacy and safety.

Technical details

The Setracker2 Android companion app (com.tgelec.setracker) versions 3.1.5 and prior suffer from a predictable identifier generation vulnerability (CWE-340). Registration IDs are derived directly from the device's IMEI, making them guessable or discoverable. Furthermore, the enrollment system lacks additional authentication factors before assigning a watch to an account. A remote attacker can exploit this to enroll unauthorized watches into their own account, gaining access to sensitive data and device functions. Mitigation involves ensuring devices are not exposed to the public internet and following general ICS-CERT defensive practices, as a specific software patch was not detailed in the advisory.

Affected products

  • Shenzhen i365-Tech Co. Ltd. Setracker2 Parental Control App (Android) package com.tgelec.setracker 3.1.5 and prior

Timeline

  • 2026-06-25: advisory: CISA/ICS-CERT published the advisory.
  • 2026-06-26: disclosed: NVD published the CVE record.

References

Related threats