VYPR
Unrated severityNVD Advisory· Published Feb 1, 2021· Updated Aug 5, 2024

CVE-2019-20473

CVE-2019-20473

Description

The TK-Star Q90 Junior GPS smartwatch enforces a non-PIN-protected SIM card, preventing use with a PIN and enabling easier unauthorized SIM reuse if the device is stolen.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The TK-Star Q90 Junior GPS smartwatch enforces a non-PIN-protected SIM card, preventing use with a PIN and enabling easier unauthorized SIM reuse if the device is stolen.

Vulnerability

The TK-Star Q90 Junior GPS horloge (firmware version 3.1042.9.8656) has an intentional design restriction that prevents users from configuring a PIN on the SIM card inserted into the device [1]. If a user attempts to set a PIN, the device displays a “Remove PIN and restart!” message and refuses to operate, effectively enforcing the use of an unprotected SIM card. This behavior is not a traditional software bug but a deliberate constraint built into the device's firmware.

Exploitation

An attacker who physically steals or gains temporary access to the device can remove the SIM card and insert it into another phone or modem [1]. Because the SIM card has no PIN lock, the attacker can immediately use the card for its cellular services (voice, SMS, data) without needing to bypass any SIM-level authentication. No additional authentication or user interaction beyond physical possession of the device is required.

Impact

The successful exploitation results in a loss of confidentiality and availability of the SIM card’s services. The attacker gains the ability to make calls, send messages, or use mobile data using the victim’s mobile subscription, potentially incurring charges or exposing private communications. The legitimate user cannot prevent this by setting a PIN, as the device prohibits it [1]. This design flaw undermines basic SIM theft protection.

Mitigation

As of the last available reference (February 2021), TK-Star has not released a firmware update or workaround to allow PIN-protected SIM cards [1], [2]. Users are advised to physically secure the device to prevent theft, and to contact the vendor for possible future updates. No known fix is documented in the disclosed references. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • TK-Star/Q90 Junior GPS horlogedescription
  • star/starllm-fuzzy
    Range: =3.1042.9.8656

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.