Description
The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow.
Published: 2026-08-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Mira hormone monitor firmware allows a 0x01 write command from any Bluetooth Low Energy central without requiring device authentication, which causes the device to reboot into bootloader mode. This denial‑of‑service flaw can interrupt ovulation tracking and fertility monitoring functionality. The weakness is a classic authentication failure, classified as CWE‑306.

Affected Systems

The affected vendor is Quanovate Tech Inc., operating as Mira / Mira Care. Vulnerable products include the Mira Android App and the Mira firmware. Devices running firmware older than v01.07.01.53 are potentially impacted, and Android applications prior to version 4.5.18 (iOS prior to 3.5.18) are likewise vulnerable.

Risk and Exploitability

The CVSS base score is 7.1 and the EPSS score is below 1 %, indicating that while the flaw is technically straightforward to exploit, it is not actively seen in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, involving a BLE central within proximity to the device that can send an unauthenticated write. No special privileges or credentials are required beyond proximity to the device.

Generated by OpenCVE AI on August 12, 2026 at 19:37 UTC.

Remediation

Vendor Solution

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.


OpenCVE Recommended Actions

  • Update the Mira Android App to version 4.5.18 (or iOS to version 3.5.18).
  • Update the device firmware to v01.07.01.53 using the Mira app.
  • If application of the patch is delayed, temporarily disable BLE functionality on the device or limit connections to trusted peripherals until the update can be applied.

Generated by OpenCVE AI on August 12, 2026 at 19:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Quanovate Tech
Quanovate Tech mira Android App
Quanovate Tech mira Firmware
Vendors & Products Quanovate Tech
Quanovate Tech mira Android App
Quanovate Tech mira Firmware

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow.
Title Mira Hormone Monitor, Mira Android App Missing authentication for critical function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Quanovate Tech Mira Android App Mira Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-12T12:50:41.904Z

Reserved: 2026-08-03T16:54:56.469Z

Link: CVE-2026-66098

cve-icon Vulnrichment

Updated: 2026-08-12T12:49:35.503Z

cve-icon NVD

Status : Received

Published: 2026-08-11T22:18:49.740

Modified: 2026-08-12T13:17:23.793

Link: CVE-2026-66098

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:48:59Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function