CVE-2019-20471: Tk-Star q90 Junior Gps Horloge Firmware

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup, a default password is used (123456) for administrative purposes. There is no prompt to change this password. Note that this password can be used in combination with CVE-2019-20470.

Affected products

  • Tk-Star q90 Junior Gps Horloge Firmware: version 3.1042.9.8656 only

Published 2021-02-01. Last modified 2026-06-17.