Representative ImageSETracker app, from the Chinese developer 3G Electronics, that was reported to have some serious security flaws has finally fixed those. Required to be used with the smartwatches, the app allows an unrestricted server to server API. With this security flaw, the server was vulnerable to be used by bad actors to hijack the SETracker service like changing device passwords, making calls, sending text messages, conducting surveillance, and accessing cameras embedded in devices. However, 3G-Electronics was quick to respond to the researchers and fixed the vulnerability, and changed the exposed passwords.
"In this case, as a result of a vulnerability in the control interface of the device, or API (Application Programming Interface), an attacker could gain control and deliver messages through it. As one of the functionalities of the smartwatch is to remind the user to take their pills, the attacker could simply trigger more alerts than permitted; therefore, endangering the user's life as they could overdose. This is just one example of how the device could be manipulated. Sending fraudulent messages, controlling SMS traffic, blocking the GPS trackers on the watch or even accessing the camera as well as images on these devices are only some of the many capabilities the attacker could abuse. Furthermore, the publicly available source code for some applications has serious flaws affecting hardcoded credentials, server information of the SETwracker ecosystem database access and more," says Boris Cipot, Senior Security Engineer, at Synopsys Software Integrity Group.