CVE-2026-9222 CRITICAL

CVE-2026-9222: Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication

Vendor Shenzhen I365-Tech Co. Ltd.
Product Setracker2 Parental Control App (Android) package com.tgelec.setracker
Weakness CWE-836
Published June 25, 2026
Last update August 3, 2026

CVSS base score

9.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.

Key dates

02Disclosure timeline

June 25, 2026 CVE published
August 3, 2026 Record updated