Flaws in Smartwatches on Amazon.com May Let Strangers Track Kids

The smartwatches have a default password of "123456," which isn’t even mentioned in one smartwatch’s manual.

Advertisement
By Andrew Martin, Bloomberg | Updated: 12 December 2019 10:42 IST
Highlights
  • Security researchers discovered vulnerabilities in cheap smartwatches
  • The devices offer location tracking, messaging, and chat features
  • The watches have a default password of "123456"

The watches let authorised users change configuration details by texting the watch directly

Security researchers discovered vulnerabilities in cheap smartwatches for children that make it possible for strangers to override parental controls and track kids. Rapid7, a cyber-security firm based in Boston, purchased three smartwatches on Amazon.com, costing from $20 to $35 (roughly Rs. 1,400 to Rs. 2,500), according to Deral Heiland, research lead for IoT technology. He said the models - GreaSmart Children's SmartWatch, Jsbaby Game Smart Watch, and SmarTurtle Smart Watch for Kids - were picked randomly from dozens for sale on Amazon and marketed as appropriate for grade school-aged kids.

All three devices offer location tracking, messaging, and chat features. They were manufactured in China and shared nearly identical hardware and software. They also had similar security issues, Rapid7 found.

The watches let authorised users view and change configuration details by texting the watch directly with certain commands. In practice, this didn't work and "unlisted numbers could also interact with the watch," Rapid7 said in a report.

Advertisement

This security issue could be fixed with a vendor-supplied firmware update, but "such an update is unlikely to materialise given that the providers of these devices are difficult to impossible to locate," the cyber-security firm added.

Advertisement

The watches have a default password of "123456," but one of the watch's manuals doesn't mention the password, according to the researchers. Another mentioned the password in a blog but not in its printed material. The third doesn't characterise the numbers as a password nor does it provide instructions on how to change it, according to the researchers.

"Given an unchanged default password and a lack of SMS filtering, it is possible for an attacker with knowledge of the smartwatch phone number to assume total control of the device, and therefore use the tracking and voice chat functionality with the same permissions as the legitimate user (typically, a parent)," Rapid7 said in its report.

Advertisement

An unauthorised user could shut off all the safety protocols a parent had set up on the smartwatch, Heiland said.

Rapid7 said its researchers weren't able to contact the sellers nor what they believe is the manufacturer of the watches, a Chinese company called 3g Electronics Co. The company didn't respond to a message from Bloomberg News seeking comment.

Advertisement

The GreaSmart Children's SmartWatch is no longer for sale on Amazon, according to Rapid7. GreaSmart, Jsbaby, SmarTurtle didn't respond to a requests for comment. Oltec, a merchant that sells the SmarTurtle watch on Amazon, didn't respond to a message sent via Amazon's site.

"Consumers that are concerned with the safety, privacy, and security of their IoT devices and the associated cloud services are advised to avoid using any technology that is not provided by a clearly identifiable vendor, for what we hope are obvious reasons," Rapid7 warned in its report.

© 2019 Bloomberg LP

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Rapid7, Amazon
Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Pad 2 Pro 5G Will Launch in India Soon: See Expected Features
  2. Xiaomi 17 Ultra With Leica-Tuned Cameras Confirmed to Launch Soon
  3. Ethirneechal Thodargiradhu Now Streaming on SunNXT: What You Need to Know
  4. OTT Releases of the Week: Thamma, Mrs Deshpande, Nayanam, and More
  5. Samsung Will Unveil These New Bespoke AI Devices at CES 2026
  6. Battlefield 6 Is Beating Black Ops 7 in the Race for 2025's Top-Selling Game
  7. OnePlus 15s Visits BIS Certification Website; Could Launch in India Soon
  8. Eko OTT Release Reportedly Revealed: When and Where to Watch it Online?
  9. Poco M8 Series Design Leaked, Might Arrive in These Colourways
  10. Vivo Y50e 5G, Vivo Y50s 5G Spotted on Google Play Console, May Launch Soon
  1. Adobe Firefly Platform Updated With New AI Models and Tools, Offers Limited-Time Unlimited Generations
  2. Boat Valour Ring 1 Launched in India With Heart Rate Variability Tracking, Up to 15-Day Battery Life: Price, Features
  3. Call of Duty: Black Ops 7 Was the Best-Selling Game in the US in November, but Trails Battlefield 6 in 2025
  4. Truecaller Voicemail Feature Launched for Android Users in India With Transcription in 12 Regional Languages
  5. OpenAI Starts Reviewing Third-Party App Submissions for ChatGPT Integration
  6. Google Brings Opal, an AI-Powered Mini App Builder Tool to Gemini
  7. Redmi Pad 2 Pro 5G India Launch Teased Soon After Global Debut: Expected Specifications, Features
  8. CES 2026: Samsung to Unveil Bespoke AI Laundry Combo, Jet Bot Steam Ultra Robot Vacuum, and More
  9. Samsung Exynos 2600 Details Leak Ahead of Galaxy S26 Launch; Could Be Equipped With 10-Core CPU, AMD GPU
  10. Vivo Y50e 5G, Vivo Y50s 5G Appear on Google Play Console; Mysterious Vivo Phone Listed on Certification Site
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.