Vulnerability Description
The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-2
- https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-01
FAQ
What is CVE-2026-67558?
CVE-2026-67558 is a vulnerability with a CVSS score of 7.4 (HIGH). The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentic...
How severe is CVE-2026-67558?
CVE-2026-67558 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-67558?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.