Shenzhen i365-Tech Setracker2 Parental Control App是Shenzhen i365-Tech公司的一款家长控制应用。 Shenzhen i365-Tech Setracker2 Parental Control App 3.1.5及之前版本存在加密问题漏洞,该漏洞源于使用MD5生成请求签名,可能导致攻击者反转签名以恢复会话ID,从而冒充合法用户并发出经过身份验证的API请求。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Shenzhen i365-Tech Co. Ltd. | Setracker2 Parental Control App (Android) package com.tgelec.setracker | ≤ 3.1.5 |
affected |
3.4.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Shenzhen i365-Tech Co. Ltd. | Setracker2 Parental Control App (Android) package com.tgelec.setracker | 0 ~ 3.1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9222 | 8.1 HIGH | Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for au |
| CVE-2026-9220 | 7.5 HIGH | Setracker2 Children's Smartwatch Ecosystem Use of hard-coded cryptographic key |
| CVE-2026-9219 | 6.5 MEDIUM | Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifier |
No comments yet