Impact
The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device without independently verifying the version from the device itself. An authenticated user can submit an arbitrary firmware version string for their own device, thereby bypassing vendor‑side analytics, suppressing security update prompts, and misrepresenting patch‑adoption metrics. This flaw, indexed as CWE‑807, permits an attacker to keep a device on an older firmware while appearing fully updated to the manufacturer and any monitoring services.
Affected Systems
Quanovate Tech Inc. distributes the Mira Android App and firmware under the Mira / Mira Care brand. Current versions include the iOS app v3.5.18, the Android app v4.5.18, and device firmware v01.07.01.53. Users of any earlier builds are affected until they upgrade to these specified releases. No other vendors are listed.
Risk and Exploitability
The CVSS score of 5.3 classifies the vulnerability as moderate severity. The EPSS score of less than 1% suggests a very low probability that the flaw will be actively exploited in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires authenticated access to a device via the companion app, meaning the attacker must possess valid user credentials. Once compromised, the attacker can evade update enforcement on that device but cannot affect other devices without similar access.
OpenCVE Enrichment