Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f7c5-2gv6-7rwj

Опубликовано: 26 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.2
CVSS3: 8.1

Описание

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.

EPSS

Процентиль: 15%
0.00242
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-836

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 месяца назад

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.

EPSS

Процентиль: 15%
0.00242
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-836