Description
In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates.
Published: 2026-08-11
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote unauthenticated attacker within Bluetooth Low Energy (BLE) proximity can silently rebind the Mira hormone monitor device to an attacker‑controlled account, exposing stored hormone measurements in clear text, inducing a denial‑of‑service via malformed commands, and passively tracking the user through a static random BLE address that never changes. The flaw stems from missing authentication controls, a weakness identified as CWE‑306.

Affected Systems

The affected software is the Mira Android App and Mira firmware (v1.7.1.47 build 01070147) released by Quanovate Tech Inc., operating as Mira / Mira Care. The latest app versions are Android v4.5.18 and iOS v3.5.18, while the patched firmware is v01.07.01.53. These devices communicate over BLE in the 10–30 meter range.

Risk and Exploitability

The CVSS score of 8.7 marks this vulnerability as high severity. While the EPSS score is reported as less than 1 %, indicating a low overall exploitation probability, the attack vector is fairly straightforward for an attacker within range: no authentication is required, a simple BLE connection can rebind the device, and the attacker can immediately obtain sensitive data. Because the vulnerability is not listed in the CISA KEV catalog, no known widespread attacks have been reported yet, but the potential impact on personal health data and device integrity warrants rapid remediation.

Generated by OpenCVE AI on August 12, 2026 at 19:19 UTC.

Remediation

Vendor Solution

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.


OpenCVE Recommended Actions

  • Update the Mira Android and iOS applications to the latest releases (Android v4.5.18, iOS v3.5.18); the firmware will be upgraded automatically to v01.07.01.53 when the device is connected.
  • Verify that the firmware has been updated to v01.07.01.53; if not, disconnect the device and reinstall the latest app to trigger the upgrade.
  • If an immediate update is not possible, temporarily disable or block the device’s Bluetooth radio when not in use, or store the device in a location where BLE range is minimized to reduce the attack window.

Generated by OpenCVE AI on August 12, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Quanovate Tech
Quanovate Tech mira Android App
Quanovate Tech mira Firmware
Vendors & Products Quanovate Tech
Quanovate Tech mira Android App
Quanovate Tech mira Firmware

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates.
Title Mira Hormone Monitor, Mira Android App Missing authentication for critical function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Quanovate Tech Mira Android App Mira Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-12T12:48:32.842Z

Reserved: 2026-08-03T16:54:56.466Z

Link: CVE-2026-66875

cve-icon Vulnrichment

Updated: 2026-08-12T12:48:23.203Z

cve-icon NVD

Status : Received

Published: 2026-08-11T22:18:54.587

Modified: 2026-08-12T13:17:23.933

Link: CVE-2026-66875

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:48:57Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function