CVE-2026-66875: Quanovate Tech Inc. Operating As Mira / Mira Care Mira Android App

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates.

Affected products

Published 2026-08-11. Last modified 2026-09-03.