CVE-2026-66098
Received Received - Intake

Mira Hormone Monitor Firmware Bootloader Mode DoS

Vulnerability report for CVE-2026-66098, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-12

Assigner: ICS-CERT

Description

The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
mira hormone_monitor_device to 1.7.1.47 (inc)
mira companion_app to 4.5.15.4 (inc)
mira hormone_monitor_device_firmware 01.07.01.53
mira ios_app 3.5.18
mira android_app 4.5.18

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Mira hormone monitor device firmware has a flaw where it accepts an unauthenticated 0x01 write command from any Bluetooth Low Energy (BLE) central device. This causes the device to reboot into bootloader mode, leading to a denial-of-service condition that disrupts ovulation tracking and fertility monitoring workflows.

Detection Guidance

This vulnerability involves a Mira hormone monitor device accepting unauthenticated BLE commands. Detection requires checking for unauthorized BLE write commands (0x01) targeting the device. Use BLE scanning tools like hcitool or bluetoothctl to monitor for unexpected connections or writes to the device.

Impact Analysis

An attacker could exploit this vulnerability to cause the Mira device to reboot unexpectedly, disrupting its normal operation. This could lead to inaccurate hormone monitoring data, missed fertility tracking, or complete loss of device functionality during critical periods.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by exposing sensitive health data through unauthorized device access. A denial-of-service or bootloader mode disruption may lead to improper data handling or loss of monitoring integrity, violating privacy and security requirements under these regulations.

Mitigation Strategies

Immediately restrict physical access to the Mira device to prevent unauthorized BLE interactions. Disable unnecessary BLE services on the device if possible. Update the firmware to a patched version if available. Monitor device logs for unexpected reboots or bootloader activations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66098. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart