CVE-2026-9222: Shenzhen i365-Tech Co. Ltd SETRACKER2 Parental Control App Android Package Com.tgelec.setracker
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.
Affected products
- Shenzhen i365-Tech Co. Ltd SETRACKER2 Parental Control App Android Package Com.tgelec.setracker: up to and including 3.1.5; version 3.4.1 only
Published 2026-06-26. Last modified 2026-08-03.