CVE-2026-9221Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between the mobile client and the backend REST API. Attackers could potentially reverse the signature to recover the session ID. With the session ID exposed, an attacker could impersonate the legitimate user and issue authenticated API requests.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-26: 3Technical Details · 2026-06-26: 306-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-9221 MD5 Signature Weakness in Setracker2 Android App Versions ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9221 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A tweet cites CVE-2026-9221, noting an MD5 signature weakness in Setracker2 Android apps, but it offers no PoC, exploit details, patch information, or evidence of active exploitation.

    0000096
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-9221 The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications betwee… https://www.cve.org/CVERecord?id=CVE-2026-9221 ----- Traducción: CVE-2026-9221 La … http://infoflow.cloud`

    Post summary

    A brief disclosure of CVE-2026-9221, highlighting an MD5‑based request signature flaw in the Setracker2 Android Companion App without any PoC, exploit code, patch, or active exploitation information.

    0000037
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-9221 The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications betwee… https://www.cve.org/CVERecord?id=CVE-2026-9221

    Post summary

    The CVE is disclosed, outlining that Setracker2 uses MD5 for request signatures; no exploitation or patch information is provided.

    00000813
    57.7K followersView on X

Explore more