nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-9222 CVE-2026-9222
CRITICAL
Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication
Record summary
CVE-2026-9222 has a selected CVSS score of 9.2 (critical).
Description
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 26, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Setracker2 Parental Control App (Android) package com.tgelec.setrackerBrowse Shenzhen i365-Tech Co. Ltd. / Setracker2 Parental Control App (Android) package com.tgelec.setrackerDefault status: unaffected | CVE List | Through 3.1.5 | affected |
| 3.4.1 | affected |
References
2raw.githubusercontent.com
https://raw.githubusercontent.com/cisagov/CSAF/refs/heads/develop/csaf_files/VA/white/2026/va-26-176-01.json