Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.
References
Configurations
No configuration.
History
26 Jun 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-26 00:16
Updated : 2026-06-26 20:08
NVD link : CVE-2026-9222
Mitre link : CVE-2026-9222
CVE.ORG link : CVE-2026-9222
JSON object : View
Products Affected
No product.
CWE
CWE-836
Use of Password Hash Instead of Password for Authentication
