What is CVE-2026-66875?
CVE-2026-66875 is a vulnerability in Mira hormone monitor firmware v1.7.1.47 allowing a remote unauthenticated attacker within BLE range to silently rebind the device, extract cleartext stored hormone measurements, and cause a denial-of-service. Users should await a firmware patch from the vendor to mitigate the risk.
Azərbaycanca: CVE-2026-66875 Mira hormon monitor cihazının proqram təminatında (firmware v1.7.1.47) BLE vasitəsilə uzaqdan autentifikasiya olunmamış giriş imkanıdır. Təcavüzkar cihazı öz hesabına bağlaya, hormon məlumatlarını şifrəsiz əldə edə və xidmət rəddi (DoS) yarada bilər. Cihazın BLE diapazonunda (10-30m) təhlükədən qorunmaq üçün firmware yeniləməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Mira
FAQ2
What actions can an attacker perform by exploiting CVE-2026-66875?
An attacker can silently rebind the Mira hormone monitor to their own account, extract cleartext stored hormone measurements, and cause a denial-of-service.
What mitigation is recommended for CVE-2026-66875?
Users should await a firmware patch from the vendor and, in the meantime, be aware of the risk within the device's BLE range (10-30 meters).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.