CRITICAL🇵🇱 Wersja polska

CVE-2026-9222

CVSS 9.2v4.0pub. 2026-06-26upd. 2026-08-03

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.

🤖 AI Analysis
How it works

The application, when logging into backend services, transmits only the hash of the user's password, without applying additional verification mechanisms (e.g., challenge-response). This means the hash serves as an authenticating identity — it is sufficient to intercept it or obtain it from another source (e.g., database leak, network traffic sniffing). An attacker who possesses the hash can directly authenticate in the application's backend and take over the victim's account (pass-the-hash attack).

Impact

An attacker who knows the user's password hash can authenticate in the Setracker2 backend and gain full access to the account, including tracking data and device management associated with the application.

Mitigation & patch

Apply patches available from the manufacturer according to the references. It is recommended to update the application to a version newer than 3.1.5, which should implement a secure authentication mechanism that does not rely solely on password hash transmission.

Who is affected

Setracker2 application for Android (com.tgelec.setracker) in version 3.1.5 and earlier.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References