VYPR
Unrated severityNVD Advisory· Published Feb 1, 2021· Updated Aug 8, 2024

CVE-2019-20471

CVE-2019-20471

Description

TK-Star Q90 Junior GPS watch uses a hardcoded default administrative password (123456) with no prompt to change it, enabling unauthorized access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

TK-Star Q90 Junior GPS watch uses a hardcoded default administrative password (123456) with no prompt to change it, enabling unauthorized access.

Vulnerability

The TK-Star Q90 Junior GPS horloge (firmware version 3.1042.9.8656) ships with a hardcoded default administrative password of 123456. During initial setup, the device does not prompt the user to change this password, leaving the administrative interface accessible with known credentials [1].

Exploitation

An attacker who can reach the device's administrative interface (e.g., over the network or via Bluetooth) can authenticate using the default password 123456. No prior authentication or user interaction is required. The password can also be used in conjunction with another vulnerability (CVE-2019-20470) to escalate access [1].

Impact

Successful exploitation grants the attacker full administrative control over the device. This can lead to unauthorized access to sensitive data (e.g., location history, personal information), modification of device settings, or further compromise of the device and associated accounts [1].

Mitigation

As of the publication date (2021-02-01), no firmware update or official workaround has been released by TK-Star to address this issue. Users are advised to contact the vendor for guidance and to monitor for future updates. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog [2].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • TK-Star/Q90 Junior GPS horlogedescription
  • star/starllm-fuzzy
    Range: = 3.1042.9.8656

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.