CVE-2026-66875: Mira Hormone Monitor, Mira Android App Missing authentication for critical function
In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mira Android Appto a version that resolves this vulnerability.Fixed in v4.5.18 - Upgrade
Upgrade
Mira iOS Appto a version that resolves this vulnerability.Fixed in v3.5.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66875?
The severity of CVE-2026-66875 is high, with a score of 8.8.
How do I fix CVE-2026-66875?
To fix CVE-2026-66875, update the Mira hormone monitor device firmware to the latest version that addresses this vulnerability.
What kind of attack can be conducted due to CVE-2026-66875?
CVE-2026-66875 allows a remote unauthenticated attacker to rebind the device, extract hormone data, and potentially cause a denial-of-service.
Who is affected by CVE-2026-66875?
CVE-2026-66875 affects users of the Mira hormone monitor and Mira Android app running vulnerable firmware version 1.7.1.47.
What is the potential impact of CVE-2026-66875?
The potential impact of CVE-2026-66875 includes exposure of sensitive hormone measurement data and disruption of device functionality.