CVE-2026-9219
Received Received - Intake
Predictable Registration ID Enables Unauthorized Watch Enrollment in Setracker2

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: ICS-CERT

Description
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging to other users.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
com.tgelec setracker to 3.1.5 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-340 The product uses a scheme that generates numbers or identifiers that are more predictable than required.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-9219 affects the Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier. The vulnerability involves a predictable registration ID that is derived from the device's IMEI number.

Because the enrollment system does not require additional authentication before assigning the registration ID, an attacker who obtains this predictable registration ID can arbitrarily enroll watches that belong to other users.

Impact Analysis

This vulnerability can allow an attacker to enroll and potentially control watches belonging to other users without their permission.

Such unauthorized enrollment could lead to privacy violations, unauthorized access to user data, and misuse of the devices.

Since the vendor has been unresponsive and no known remediations are available, affected users are advised to contact the vendor or their local supplier for further guidance.

Detection Guidance

This vulnerability involves a predictable registration ID derived from the device's IMEI used by the Setracker2 Android Companion App. Detection would require monitoring for unusual or unauthorized enrollment attempts of watches using registration IDs that could be predicted or derived from IMEI values.

No specific detection commands or tools are provided in the available information.

Mitigation Strategies

Since the vendor has been unresponsive and no known remediations are available, affected users are advised to contact the vendor or their local supplier for further guidance.

Additionally, users should monitor for unauthorized enrollments and consider limiting exposure of IMEI information to reduce the risk of attackers obtaining predictable registration IDs.

Compliance Impact

The provided information does not specify how the vulnerability in Setracker2 Android Companion App affects compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9219. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart