Our Approach to Platform Security
Security has been a consistent focus throughout SETracker's development. Since the platform launched, our team has maintained a regular cadence of server updates, bug fixes, and security hardening — all documented in our public update record. When security concerns are brought to our attention — whether through internal audits, external researchers, or regulatory review — we treat them as urgent priorities; that approach has not changed.
What We Identified and Fixed
In early August 2026, independent security researchers presented findings at DEF CON regarding vulnerabilities affecting several GPS watch platforms, including SETracker. We take this research seriously and have addressed the specific issues identified. Here is a transparent account of what was fixed.
1. Port 8081 — Blocked and Closed
A small number of devices still running older versions of the SETracker application were using Port 8081 for communication. This port represented a potential point of remote exploitation. We implemented a full block on Port 8081, eliminating any risk of it being used to remotely access or control devices. Simultaneously, we issued server-side push notifications to force all affected active devices to upgrade to the latest application build, ensuring no active users remain on vulnerable older versions.
2. Device Registration ID Mechanism — Upgraded
In early 2017, we migrated from the legacy IMEI-based device identification system to a more secure server-side dynamic ID allocation scheme. Under this system, each device is assigned a randomized ID — such as gb266d8ajn — generated and managed by our servers, rather than derived from the device's hardware identifier. This significantly reduces the risk of unauthorized ID-based access. The vast majority of our clients have been operating on this more secure system for years. A small number of clients had continued to use the legacy mechanism due to historical business requirements; we have contacted each of these clients individually and guided them through the transition to the current automatic ID allocation framework.
3. Ongoing Application Security Updates
Across all versions of the SETracker application — including standard, neutral, and customized builds — we have rolled out multiple iterations of security mechanism updates in line with data security and privacy compliance requirements. These updates cover data handling protocols, transmission security, and privacy controls.
What This Means for Your Devices
For distributors, brand partners, and end users currently operating Wonlex devices on the SETracker platform, no action is required.
The security improvements described in this update were implemented at the server and platform levels, so all active devices automatically benefit from these fixes. There is no firmware update to install and no account changes required. All in-service devices and backend services are currently in a secure and stable state.
For partners operating customized versions of the SETracker application, our team has been in direct contact to ensure your specific deployment has been reviewed and updated accordingly.
If you have specific questions about your deployment or would like a technical briefing, please
contact us directly.
Our Ongoing Security Commitments
Addressing a security concern is only part of the work. What matters more is what comes next. Going forward, Wonlex is committed to the following:
- Regular security audits: We regularly conduct internal vulnerability assessments and continue to enhance their frequency as the threat landscape evolves.
- Proactive patching: When vulnerabilities are identified — internally or externally — we promptly assess their impact and deploy necessary fixes.
- GDPR and data privacy compliance: SETracker operates in full compliance with GDPR requirements for European markets. Data handling, storage, and privacy practices are reviewed regularly in line with current regulatory standards.
- Transparent communication: We will continue to maintain our public update record and issue security statements when significant changes are made to the platform.
The GPS smartwatch industry carries a real responsibility — the devices we make are worn by children, and the data they handle is sensitive. We take that responsibility seriously, and we will continue to earn the trust of the families, brands, and distributors who rely on Wonlex products.