CVE-2026-67558
Received Received - Intake

Mira Android App BLE Session Token Injection

Vulnerability report for CVE-2026-67558, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-12

Assigner: ICS-CERT

Description

The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mira android_companion_app 4.5.15.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Mira Android companion app v4.5.15.4 has a security flaw where it identifies paired Mira hormone analyzers by checking only the BLE advertisement name using a substring match. This method lacks cryptographic peripheral authentication, MAC allowlist checks, or bonded-identity verification. As a result, attackers can capture live session tokens and inject forged hormone measurements into the victim's cloud records and clinical trend views.

Detection Guidance

Detecting this vulnerability requires checking for unsecured BLE communications between the Mira Android app and the hormone analyzer. Monitor BLE traffic for unencrypted session tokens or forged advertisement names. Use tools like Wireshark with BLE support or hcitool to scan for Mira device advertisements without cryptographic checks.

Impact Analysis

This vulnerability allows attackers to manipulate hormone measurement data in your cloud records and clinical trend views. They can forge data, leading to incorrect medical records, misdiagnosis, or inappropriate treatment decisions based on falsified information.

Compliance Impact

This vulnerability could lead to unauthorized modification of hormone measurement data in clinical records, potentially violating data integrity requirements under GDPR and HIPAA. Unauthorized access to session tokens and forged measurements may also breach confidentiality and security controls mandated by these regulations.

Mitigation Strategies

Disable BLE connectivity for the Mira app until an update is available. Avoid using the app in untrusted environments. Contact Mira support for a patched version. Implement network segmentation to isolate the device if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67558. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart