Impact
Based on the title, it is inferred that the vulnerability arises from the use of hard‑coded credentials within the Mira Android application. These credentials enable an attacker to read or modify reproductive health profiles stored on an internet‑connected host, potentially facilitating the forgery of records, deletion of data, or destruction of sensitive health information.
Affected Systems
Vulnerable assets include the Mira Android app (v4.5.15.4) and the accompanying Mira firmware. The affected vendor is Quanovate Tech Inc., operating as Mira / Mira Care. Users should upgrade to the Mira Android app version 4.5.18 and firmware version 01.07.01.53.
Risk and Exploitability
The CVSS score of 9.3 classifies this issue as critical, yet the EPSS score of <1% indicates that exploits are rare and the vulnerability is not listed in the CISA KEV catalog. The flaw can be abused by any entity that obtains or reverse‑engineers the app, making the attack vector primarily client‑side on an internet‑connected host. Successful exploitation grants complete read/write authority over personal medical data, posing significant confidentiality and integrity risks.
OpenCVE Enrichment