CyberRota Analysis
AI-GeneratedThe Mira hormone monitor device firmware is vulnerable to remote unauthenticated attacks within Bluetooth Low Energy (BLE) range, allowing attackers to rebind the device to their own account and access sensitive hormone measurement data in cleartext. Additionally, attackers can induce a denial-of-service through malformed commands and track users due to a static BLE address that does not change. Healthcare organizations and users of the Mira device should prioritize addressing this vulnerability to protect sensitive health data and ensure device integrity.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates.