← Back

Itrack Easy

itrack_easy

Vendor: Ieasytec • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ieasytec
1Itrack Easy
Nov 21, 2024
Jul 13, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be exploited to alter the GPS data of a lost device.
1Ieasytec
1Itrack Easy
Nov 21, 2024
Jul 13, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS data, which can allow unauthenticated parties to track the device.