CVE-2026-9220Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 watch traffic.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-26: 3Technical Details · 2026-06-26: 306-26
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9220 Static AES Encryption Keys in Setracker2 Android App Versions 3.1.5 and Prior https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9220

    Post summary

    The post announces vulnerability CVE-2026-9220 involving static AES keys in Setracker2 Android app versions, but does not provide PoC, exploit, active usage, or patch details.

    0000087
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-9220 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and in… https://www.cve.org/CVERecord?id=CVE-2026-9220 ----- Traducción: CVE-2026-9220 Set… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-9220, noting that Setracker2 Android Companion App versions 3.1.5 and earlier store static hardcoded AES keys, but offers no PoC, exploit, or mitigation details.

    0000036
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-9220 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and in… https://www.cve.org/CVERecord?id=CVE-2026-9220

    Post summary

    The post describes a CVE involving hardcoded AES keys in the Setracker2 Android Companion App, without mentioning PoCs, exploits, or patches.

    00000665
    57.7K followersView on X

Explore more