CVE-2026-66098: Quanovate Tech Inc. Operating As Mira / Mira Care Mira Android App
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow.
Affected products
- Quanovate Tech Inc. Operating As Mira / Mira Care Mira Android App: version 4.5.15.4 only
- Quanovate Tech Inc. Operating As Mira / Mira Care Mira Firmware: version 1.7.1.47 only
Published 2026-08-11. Last modified 2026-09-03.