CVE-2026-9219Disclosure

LOWCVSS 8.3 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able to arbitrarily enroll watches belonging to other users.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-340

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-26: 3Technical Details · 2026-06-26: 306-26
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9219 Arbitrary Watch Enrollment in Setracker2 Android App via Predictable Registration ID https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9219

    Post summary

    The text announces a new vulnerability in the Setracker2 Android app that enables arbitrary watch enrollment through a predictable registration ID, but it provides no proof-of-concept, exploit code, patch, or evidence of active exploitation.

    0000084
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-9219 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additio… https://www.cve.org/CVERecord?id=CVE-2026-9219 ----- Traducción: CVE-2026-9219 Set… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-9219, noting a predictable registration ID vulnerability in the Setracker2 Android Companion App without providing PoC, exploit tools, or patch information.

    0000059
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-9219 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additio… https://www.cve.org/CVERecord?id=CVE-2026-9219

    Post summary

    CVE‑2026‑9219 exposes a predictable registration ID derived from the device IMEI in Setracker2’s Android companion app, potentially allowing unauthorized enrollment or authentication bypass.

    00000764
    57.7K followersView on X

Explore more