9.2
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.
AI Analysis
Use of password hash instead of password for authentication in Setracker2 Android Companion App
Basic Information
ID
CVE-2026-9222
Source
icscert
Published
Jun 25, 2026 at 23:29
Affected Product
Vendor
Shenzhen i365-Tech Co. Ltd.
Product
Setracker2 Parental Control App (Android) package com.tgelec.setracker
Version
3.1.5
Affected Versions
Shenzhen i365-Tech Co. Ltd. Setracker2 Parental Control App (Android) package com.tgelec.setracker 0
CWE Classification
AI Assessment
AI Score
9.2 / 10
AI Severity
Critical
Vendor
Shenzhen i365-Tech Co. Ltd.
Product
Setracker2 Parental Control App
Version
3.1.5 and prior