CVE-2026-9222
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.41%
- CWE
- CWE-836
- Published
- 2026-06-25
- Last modified
- 2026-08-03
Affected products
- Shenzhen i365-Tech Co. Ltd. Setracker2 Parental Control App (Android) package com.tgelec.setracker
- Shenzhen i365-Tech Co. Ltd. Setracker2 Parental Control App (Android) package com.tgelec.setracker
Weakness type
Related vulnerabilities
- CVE-2026-44736 — OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects
- CVE-2026-40103 — Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds
- CVE-2019-25552 — CEWE PHOTO SHOW 6.4.3 Denial of Service via Password Field
- CVE-2025-64471 — A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability...
- CVE-2025-62618 — ELOG file upload stored XSS
- CVE-2025-52543 — Login to the application services using only the password hash
- CVE-2025-48925 — The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do...
- CVE-2023-39546 — CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe...