Junglewise Threat Intelligence

CVE-2026-9221: Shenzhen i365-Tech Setracker2 weak MD5 signature in Android app

CVE-2026-9221 · Severity: high · CVSS 7.5 · Published 2026-06-26

Executive brief

The Setracker2 Android app, used for managing children's smartwatches, uses an outdated and weak security method to sign its communications. An attacker could exploit this weakness to steal a user's session ID, allowing them to impersonate parents and access sensitive account information or issue commands to the smartwatch. This could lead to unauthorized tracking or communication with the device.

Technical details

The Setracker2 Android app (com.tgelec.setracker) utilizes the MD5 hashing algorithm to generate request signatures for its backend REST API. Due to the cryptographic weaknesses of MD5, an attacker can potentially reverse the signature to recover the session ID. This vulnerability is classified as CWE-327 (Use of a Broken or Risky Cryptographic Algorithm). Successful exploitation allows a remote, unauthenticated attacker to obtain a valid session ID and perform unauthorized API requests as the victim. The vulnerability affects versions 3.1.5 and earlier; users are advised to update to the latest version if available.

Affected products

  • Shenzhen i365-Tech Co. Ltd. Setracker2 Parental Control App (Android) package com.tgelec.setracker <= 3.1.5

Timeline

  • 2026-06-25: advisory: CISA/ICS-CERT published the advisory.
  • 2026-06-26: disclosed: CVE published to NVD.

References