CVE-2026-9219 HIGH

CVE-2026-9219: Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers

Vendor Shenzhen I365-Tech Co. Ltd.
Product Setracker2 Parental Control App (Android) package com.tgelec.setracker
Weakness CWE-340
Published June 25, 2026
Last update August 3, 2026

CVSS base score

8.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging to other users.

Key dates

02Disclosure timeline

June 25, 2026 CVE published
August 3, 2026 Record updated