An issue was discovered in SeTracker2 for TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It has unnecessary permissions such as READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE, and READ_CONTACTS.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.tk-star.com | vendor advisory |
https://www.eurofins-cybersecurity.com/news/connected-devices-smart-watches/ | third party advisory |
http://seclists.org/fulldisclosure/2024/Jul/14 | mailing list |