Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.
The application, when logging into backend services, transmits only the hash of the user's password, without applying additional verification mechanisms (e.g., challenge-response). This means the hash serves as an authenticating identity — it is sufficient to intercept it or obtain it from another source (e.g., database leak, network traffic sniffing). An attacker who possesses the hash can directly authenticate in the application's backend and take over the victim's account (pass-the-hash attack).
An attacker who knows the user's password hash can authenticate in the Setracker2 backend and gain full access to the account, including tracking data and device management associated with the application.
Apply patches available from the manufacturer according to the references. It is recommended to update the application to a version newer than 3.1.5, which should implement a secure authentication mechanism that does not rely solely on password hash transmission.
Setracker2 application for Android (com.tgelec.setracker) in version 3.1.5 and earlier.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X