Impact
The Mira hormone monitor firmware allows a 0x01 write command from any Bluetooth Low Energy central without requiring device authentication, which causes the device to reboot into bootloader mode. This denial‑of‑service flaw can interrupt ovulation tracking and fertility monitoring functionality. The weakness is a classic authentication failure, classified as CWE‑306.
Affected Systems
The affected vendor is Quanovate Tech Inc., operating as Mira / Mira Care. Vulnerable products include the Mira Android App and the Mira firmware. Devices running firmware older than v01.07.01.53 are potentially impacted, and Android applications prior to version 4.5.18 (iOS prior to 3.5.18) are likewise vulnerable.
Risk and Exploitability
The CVSS base score is 7.1 and the EPSS score is below 1 %, indicating that while the flaw is technically straightforward to exploit, it is not actively seen in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, involving a BLE central within proximity to the device that can send an unauthenticated write. No special privileges or credentials are required beyond proximity to the device.
OpenCVE Enrichment