Executive brief
The Setracker2 Android app, used to manage children's smartwatches and parental controls, contains a security flaw in how it verifies users. An attacker who obtains a user's password hash can bypass the login process entirely to gain full access to the account. This could allow unauthorized individuals to track locations, view sensitive personal information, or manipulate device functions.
Technical details
The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and prior are vulnerable to an authentication bypass (CWE-836). The application's backend services only require a password hash rather than the actual plaintext password to authenticate client requests. An attacker who obtains the password hash through other means (such as data breaches or local interception) can replay or submit this hash to the backend to gain full unauthorized access to the user's account and associated smartwatch data. The vulnerability is reachable over the network, though it requires the attacker to have prior knowledge of the specific target's password hash.
Affected products
- Shenzhen i365-Tech Co. Ltd. Setracker2 Parental Control App (Android) package com.tgelec.setracker 3.1.5 and prior
Timeline
- 2026-06-25: advisory: CISA/ICS-CERT published the advisory.
- 2026-06-26: disclosed: NVD published the CVE record.