An issue was discovered on TK-Star Q90 Junior GPS horloge...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Aug 1, 2024
Description
Published by the National Vulnerability Database
Feb 1, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Aug 1, 2024
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SMS commands. This can be used to set up a voice communication channel from the watch to any telephone number, initiated by sending a specific SMS and using the default password, e.g., pw,,call,<mobile_number> triggers an outbound call from the watch. The password is sometimes available because of CVE-2019-20471.
References