Executive brief
The Mira hormone monitor is a medical device that helps women track fertility and ovulation. An attacker with Bluetooth proximity can send a single command to force the device to reboot into bootloader mode without any authentication, disrupting fertility tracking workflows and causing customer frustration. This impacts the reliability of health monitoring for women trying to conceive.
Technical details
The vulnerability is a missing authentication vulnerability (CWE-306) in the Mira hormone monitor device firmware v1.7.1.47. The firmware accepts a 0x01 write command via Bluetooth Low Energy (BLE) from any unpaired central device without requiring authentication or authorization. An attacker within BLE range (approximately 10–30 meters) can trigger a device reboot into bootloader mode by sending this command, causing denial-of-service. The attack requires no user interaction, no prior authentication, and no knowledge of the device identity. Patches are available in firmware v01.07.01.53 and Mira app version 4.5.18 (iOS) / 4.5.18 (Android).
Affected products
- Quanovate Tech Inc. (operating as Mira) Mira Hormone Monitor 1.7.1.47
- Quanovate Tech Inc. (operating as Mira) Mira Android App 4.5.15.4
Timeline
- 2026-08-11: disclosed: CISA ICS Medical Advisory ICSMA-26-223-01 published
- 2026-08-11: patched: Firmware v01.07.01.53 and Mira app v4.5.18 (iOS/Android) available