CVE-2026-9222CWE-836

CVE-2026-9222

High · published June 26, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
34.5
In the wild
Unconfirmed
What it is

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00412 · 34.5th percentile
Weakness
CWE-836 · Use of Password Hash Instead of Password for Authentication
Published
2026-06-26T04:16Z
References (1)
EPSS history
Timeline
  • 25 JUN 23:29Z
    Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication
    cvelistv5