Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection. An attacker with physical access to the device can use a standard SPI programmer to extract the firmware using flashrom. This results in exposure of sensitive configuration data such as APN credentials, backend server information, and network parameter
| Software | From | Fixed in |
|---|---|---|
| meitrack / t366l-g_firmware | t366l_y24h131v039 | t366l_y24h131v039.x |