An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup, a default password is used (123456) for administrative purposes. There is no prompt to change this password. Note that this password can be used in combination with CVE-2019-20470.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://www.tk-star.com | vendor advisory |
https://www.eurofins-cybersecurity.com/news/connected-devices-smart-watches/ | third party advisory |
http://seclists.org/fulldisclosure/2024/Jul/14 | mailing list |