nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-9219 CVE-2026-9219
HIGH
Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers
Record summary
CVE-2026-9219 has a selected CVSS score of 8.3 (high).
Description
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging to other users.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 26, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Setracker2 Parental Control App (Android) package com.tgelec.setrackerBrowse Shenzhen i365-Tech Co. Ltd. / Setracker2 Parental Control App (Android) package com.tgelec.setrackerDefault status: unaffected | CVE List | Through 3.1.5 | affected |
| 3.4.1 | unaffected |
References
2raw.githubusercontent.com
https://raw.githubusercontent.com/cisagov/CSAF/refs/heads/develop/csaf_files/VA/white/2026/va-26-176-01.json