Description
The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics.
Published: 2026-08-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device without independently verifying the version from the device itself. An authenticated user can submit an arbitrary firmware version string for their own device, thereby bypassing vendor‑side analytics, suppressing security update prompts, and misrepresenting patch‑adoption metrics. This flaw, indexed as CWE‑807, permits an attacker to keep a device on an older firmware while appearing fully updated to the manufacturer and any monitoring services.

Affected Systems

Quanovate Tech Inc. distributes the Mira Android App and firmware under the Mira / Mira Care brand. Current versions include the iOS app v3.5.18, the Android app v4.5.18, and device firmware v01.07.01.53. Users of any earlier builds are affected until they upgrade to these specified releases. No other vendors are listed.

Risk and Exploitability

The CVSS score of 5.3 classifies the vulnerability as moderate severity. The EPSS score of less than 1% suggests a very low probability that the flaw will be actively exploited in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires authenticated access to a device via the companion app, meaning the attacker must possess valid user credentials. Once compromised, the attacker can evade update enforcement on that device but cannot affect other devices without similar access.

Generated by OpenCVE AI on August 12, 2026 at 19:39 UTC.

Remediation

Vendor Solution

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.


OpenCVE Recommended Actions

  • Update the Mira Android App to version v4.5.18 (iOS v3.5.18 is also recommended).
  • Launch the updated app and connect the Mira device; the firmware will automatically upgrade to v01.07.01.53 via the app.
  • No additional action is required once the app and firmware are updated.

Generated by OpenCVE AI on August 12, 2026 at 19:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Quanovate Tech
Quanovate Tech mira Android App
Quanovate Tech mira Firmware
Vendors & Products Quanovate Tech
Quanovate Tech mira Android App
Quanovate Tech mira Firmware

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Description The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics.
Title Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision
Weaknesses CWE-807
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Quanovate Tech Mira Android App Mira Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-12T12:57:16.516Z

Reserved: 2026-08-03T16:54:56.490Z

Link: CVE-2026-64934

cve-icon Vulnrichment

Updated: 2026-08-12T12:57:13.303Z

cve-icon NVD

Status : Received

Published: 2026-08-11T22:18:41.897

Modified: 2026-08-12T14:18:28.447

Link: CVE-2026-64934

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:49:06Z

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision