HomeSecuritySmartwatch tracker that helps vulnerable people can be hacked

Smartwatch tracker that helps vulnerable people can be hacked

Researchers have uncovered a set of serious security issues in a smartwatch tracker used in applications, including services designed to support elderly and vulnerable people.

On Thursday, cybersecurity experts from Pen Test Partners revealed security issues found in the SETracker service, software aimed at children and the elderly – especially those with dementia or people who need reminders to complete daily tasks, such as taking medication.

Smartwatch tracker

The GPS tracker app can be used in conjunction with a smartwatch, and in turn, users can use the system to make a call if they need help.

The SETracker app, from Chinese company 3G Electronics, is available on iOS and Android and has been downloaded over 10 million times.

However, security flaws in the product showed that it wasn't just caregivers or loved ones who could monitor a user's movements or activities .

The vendor's software, of which there are now three mobile app versions, often runs in the background of inexpensive smartwatches offered by various brands. SETracker is also found in the headphone and automotive software industries.

According to Pen Test Partners, the first major security issue was the discovery of an unrestricted “server to server API.” The server could be used to compromise the SETracker service in ways that include, but are not limited to, changing device passwords , making calls , sending text messages, conducting surveillance, and accessing cameras embedded in devices.

If a monitor's support system relies on SETracker, it was possible to send fake messages, including "TAKEPILLS" commands, which are set to remind users to take their medications.

“A dementia sufferer is unlikely to remember having already taken their medication,” the researchers noted. “Overdose could easily occur.”

The researchers also found the software 's source code , which was accidentally made publicly available via a compiled node file hosted on the internet as an unprotected backup.

MySQL , email , SMS, and Redis passwords , as well as source code passwords, were available for viewing. A database containing user images was also open to abuse.

“The source code indicated that this bin was where all photos taken by devices were sent. However, this has not been confirmed,” says Pen Test Partners. “Given that the use case for these devices is primarily children, it is very likely that these images contain images of children.”

It is also not known if any of the security issues have been exploited by a hacker.

Pen Test Partners disclosed its findings to 3G Electronics on January 22. The company did not respond until February 12. Triage then followed up by disclosing the server API vulnerabilities on February 17, which were patched a day later.

On May 20, researchers reported the node problem to the vendor, and on May 29, 3G Electronics confirmed that the file had been removed and all passwords had been changed.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS