Predictable Registration ID Vulnerability in Setracker2 Android Companion App
CVE-2026-9219
8.3HIGH
What is CVE-2026-9219?
The Setracker2 Android Companion App versions prior to 3.1.5 introduces a vulnerability where the registration ID, predictable based on the device's IMEI, can be exploited by attackers. This design flaw in the enrollment system allows unauthorized parties to enroll devices belonging to other users without proper authentication checks. Consequently, this may lead to privacy breaches and unauthorized access to personal information, necessitating urgent software updates and improved security measures.
Affected Version(s)
Setracker2 Parental Control App (Android) package com.tgelec.setracker 0 <= 3.1.5
References
CVSS V4
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Huancheng Hu of Hasso Plattner Institute reported these vulnerabilities to CISA, with support from Prof. Christian Doerr.
