VYPR

Mirai

by Mirai

CVEs (6)

  • CVE-2026-68067CriAug 11, 2026
    risk 0.64cvss 9.8epss

    The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record…

  • CVE-2026-67568CriAug 11, 2026
    risk 0.59cvss 9.1epss

    The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

  • CVE-2024-45163CriAug 22, 2024
    risk 0.59cvss 9.1epss 0.01

    The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized username (such as root), or can send arbitrary…

  • CVE-2026-66875HigAug 11, 2026
    risk 0.57cvss 8.8epss

    In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a…

  • CVE-2026-66832MedAug 11, 2026
    risk 0.42cvss 6.5epss

    When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to…

  • CVE-2026-66340MedAug 11, 2026
    risk 0.34cvss 5.3epss

    The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts.