Unknown · Setracker2 Android Companion App · CVE-2026-9221
**Name of the Vulnerable Software and Affected Versions**
Setracker2 Android Companion App versions prior to 3.1.6
**Description**
The application uses MD5, a broken cryptographic hash function, to generate a request signature for authenticating communications between the mobile client and the backend REST API. This weakness allows attackers to potentially reverse the signature to recover the `session ID`. Once the `session ID` is exposed, an attacker can impersonate a legitimate user to issue authenticated API requests.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.