CVE-2026-64934
Received Received - Intake

Mira Cloud API Firmware Version Spoofing

Vulnerability report for CVE-2026-64934, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-12

Assigner: ICS-CERT

Description

The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-807 The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the Mira cloud API trusting firmware version reports from a companion app without verifying them against the actual device. An authenticated attacker could falsify firmware versions for their devices, potentially avoiding security updates or misleading patch-adoption tracking.

Detection Guidance

This vulnerability involves the Mira cloud API accepting unverified firmware version strings from companion apps. Detection requires inspecting network traffic between devices and the Mira cloud API for inconsistent firmware version reports. Monitor API logs for devices reporting versions that do not match their actual firmware. Check for discrepancies between device-reported and vendor-attested firmware versions.

Impact Analysis

An attacker could exploit this to prevent your device from receiving critical security updates, making it vulnerable to further exploits. It may also allow them to misrepresent the security status of devices in your fleet, leading to false confidence in compliance or safety.

Compliance Impact

This vulnerability could undermine compliance by providing inaccurate firmware version data, which may be used to assess security posture. For example, falsified patch metrics could lead to incorrect reporting under GDPR or HIPAA, potentially violating audit requirements or exposing systems to non-compliance penalties.

Mitigation Strategies

Verify firmware versions directly on devices rather than relying on the Mira cloud API. Implement independent attestation of firmware versions to prevent spoofing. Ensure vendor-side analytics are cross-checked with device-reported data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64934. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart