Vulnerability in Mira Hormone Monitor Device Firmware
CVE-2026-66875

8.7HIGH

What is CVE-2026-66875?

The Mira hormone monitor device firmware v1.7.1.47 is susceptible to a remote unauthenticated attack within Bluetooth Low Energy (BLE) range. An attacker can exploit this vulnerability to silently rebind the monitor to their own account, allowing them to extract sensitive hormone measurement data in cleartext. Additionally, the flaw enables the execution of denial-of-service attacks via malformed command opcodes and allows unauthorized tracking of users through a static BLE address that does not change. This poses significant privacy risks for individuals relying on this device for health management.

Affected Version(s)

Mira Android App Android 4.5.15.4

Mira Firmware 1.7.1.47

Mira Android App Android 4.5.18

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gigi Xiaoqing Liu, Muzzammil Mohammed, Narmina Karimova, and En Mong of Northeastern University SPQR Lab reported this vulnerability to Quanovate Tech.
.