← Back

Xelex

xelex

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Mobiletrack
mobiletrack

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xelex
1Mobiletrack
Apr 29, 2026
May 22, 2012
N/A· v4
N/A· v3
2.6 LOW· v2
The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP session.
1Xelex
1Mobiletrack
Apr 29, 2026
May 22, 2012
N/A· v4
N/A· v3
7.6 HIGH· v2
The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows remote attackers to execute a (1) LOCATE, (2) TRACK, (3) UPDATECFG, (4) UPDATEACCT, (5) STAT, (6) T...Show more
The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows remote attackers to execute a (1) LOCATE, (2) TRACK, (3) UPDATECFG, (4) UPDATEACCT, (5) STAT, (6) TERM, or (7) WIPE command via an SMS message.Show less