Junglewise Threat Intelligence

CVE-2026-9222: Shenzhen i365-Tech Setracker2 authentication bypass via password hash

CVE-2026-9222 · Severity: high · CVSS 8.1 · Published 2026-06-26

Executive brief

The Setracker2 Android app, used to manage children's smartwatches and parental controls, contains a security flaw in how it verifies users. An attacker who obtains a user's password hash can bypass the login process entirely to gain full access to the account. This could allow unauthorized individuals to track locations, view sensitive personal information, or manipulate device functions.

Technical details

The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and prior are vulnerable to an authentication bypass (CWE-836). The application's backend services only require a password hash rather than the actual plaintext password to authenticate client requests. An attacker who obtains the password hash through other means (such as data breaches or local interception) can replay or submit this hash to the backend to gain full unauthorized access to the user's account and associated smartwatch data. The vulnerability is reachable over the network, though it requires the attacker to have prior knowledge of the specific target's password hash.

Affected products

  • Shenzhen i365-Tech Co. Ltd. Setracker2 Parental Control App (Android) package com.tgelec.setracker 3.1.5 and prior

Timeline

  • 2026-06-25: advisory: CISA/ICS-CERT published the advisory.
  • 2026-06-26: disclosed: NVD published the CVE record.

References