Description
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging to other users.
Published: 2026-06-25
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Setracker2’s that are deterministic and directly derived from a device’s IMEI. Because the enrollment process does not enforce any additional authentication, a malicious actor who learns or guesses one of these predictable identifiers can enroll any other child’s smartwatch in the system. The attacker would then possess the same administrative capabilities as the legitimate owner, enabling remote monitoring, data extraction, or other privileged operations. This flaw therefore allows arbitrary device enrollment and potential control over a child’s wearable without requiring the user’s consent.

Affected Systems

The vulnerability affects Shenzhen i365‑Tech’s Setracker2 Parental Control Application for Android (package com.tgelec.setracker). Versions 3.1.5 and earlier are impacted. The affected ecosystem comprises children’s smartwatches that rely on the companion app to register and link to the parent’s account.

Risk and Exploitability

With a CV the flaw is considered high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no documented public exploitation yet. Nevertheless the predictability of the registration identifier makes exploitation straightforward for any adversary who can obtain the IMEI of a target read the target’s IMEI – for example through a personal interface or via a compromised phone – can craft the enrollment payload and gain control of the smartwatch. Without a vendor patch, the risk remains elevated until a corrected registration mechanism or additional authentication is introduced.

Generated by OpenCVE AI on June 26, 2026 at 01:22 UTC.

Remediation

Vendor Workaround

The vendor was unresponsive in CISA's attempts to contact for coordination. No known remediations are available. Affected users are encouraged to contact the vendor or their local supplier.


OpenCVE Recommended Actions

  • Contact Shenzhen i365‑Tech or your local supplier for guidance or a potential fix.
  • If a vendor release or mitigation is provided, apply it immediately and revoke any unused registration IDs.
  • If no vendor fix is available, temporarily disable the Setracker2 app or restrict its use to prevent new enrollments.
  • Monitor device logs for abnormal enrollment attempts that use registration IDs derived from known IMEIs, treating such events as indications of exploitation.

Generated by OpenCVE AI on June 26, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 25 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Description Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging to other users.
Title Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers
Weaknesses CWE-340
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-06-25T23:10:19.862Z

Reserved: 2026-05-21T17:34:13.252Z

Link: CVE-2026-9219

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-26T01:30:17Z

Weaknesses
  • CWE-340

    Generation of Predictable Numbers or Identifiers