Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 watch traffic.
References
Configurations
No configuration.
History
26 Jun 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-26 00:16
Updated : 2026-06-26 20:08
NVD link : CVE-2026-9220
Mitre link : CVE-2026-9220
CVE.ORG link : CVE-2026-9220
JSON object : View
Products Affected
No product.
CWE
CWE-321
Use of Hard-coded Cryptographic Key
