Thetrackr develops a line of personal tracking devices, including the Trackr Bravo and related models, with a vulnerability profile centered on authentication and data-protection weaknesses. The recurring exposure pattern spans missing or improper authentication controls, inadequate authorization enforcement, and cleartext storage of sensitive information, reflecting common security gaps in IoT tracking devices where credential management and local data protection are often underdeveloped. Live severity, exploitation status, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thetrackr over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-6541HIGH TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes. Updated apps, version 5.1.6 for iOS | Jul 6, 2018 | 8.8 | 26 | NO | NO |
CVE-2016-6538HIGH The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file. Updated apps, version 5.1.6 for iOS and 2.2.5 for A | Jul 6, 2018 | 8.8 | 26 | NO | NO |
CVE-2016-6540MEDIUM Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data for any Trackr device by using the tracker ID number which | Jul 6, 2018 | 6.5 | 20 | NO | NO |
CVE-2020-13425HIGH TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a denial of service when battery capacity is exhausted. | May 23, 2020 | 7.1 | 18 | NO | NO |
The Trackr device ID is constructed of a manufacturer identifier of four zeroes followed by the BLE MAC address in reverse. The MAC address can be obtained by being in close proxim | Jul 6, 2018 | 3.5 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thetrackr.
Media articles that mention a CVE ID that affects a product developed by Thetrackr — matched by CVE ID, not by vendor name.