CVE-2026-9222
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
26/06/2026
Last modified:
26/06/2026
Description
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.
Impact
Base Score 4.0
9.20
Severity 4.0
CRITICAL
Base Score 3.x
8.10
Severity 3.x
HIGH



