Tk Star's vulnerability footprint centers on a children's GPS wearable device, the Q90 Junior GPS Watch, with exposure identified in the device firmware. The durable signal reflects a niche hardware-embedded product rather than a broad software platform; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tk Star over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20468CRITICAL An issue was discovered in SeTracker2 for TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It has unnecessary permissions such as READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE | Feb 1, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-20470HIGH An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SMS commands. This can be used to set up a voice communication | Feb 1, 2021 | 7.5 | 25 | NO | NO |
CVE-2019-20471HIGH An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup, a default password is used (123456) for administrative purp | Feb 1, 2021 | 7.8 | 24 | NO | NO |
CVE-2019-20473MEDIUM An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device | Feb 1, 2021 | 6.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tk Star.
Media articles that mention a CVE ID that affects a product developed by Tk Star — matched by CVE ID, not by vendor name.