Executive brief
Mira's cloud authentication system does not implement rate limiting, IP throttling, or account lockout protections. An attacker can repeatedly submit login attempts without restriction, enabling brute-force attacks to gain unauthorized access to user accounts containing sensitive health and fertility tracking data.
Technical details
The vulnerability is an improper restriction of excessive authentication attempts (CWE-640) in Mira's cloud authentication endpoints. The authentication service lacks per-account rate limiting, per-IP request throttling, and account lockout mechanisms following repeated failed login attempts. An attacker with network access can conduct brute-force attacks against user accounts without triggering any protective countermeasures. No authentication is required to initiate login attempts. Patches are available: Mira Monitor Firmware v01.07.01.53 and Mira Android App v4.5.18.
Affected products
- Quanovate Tech Inc. Mira Monitor Firmware 1.7.1.47
- Quanovate Tech Inc. Mira Android App 4.5.15.4
Timeline
- 2026-08-11: disclosed