Critical Security Flaws Found in Mira Hormone Monitor Devices and App
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory covering eight vulnerabilities in the Mira Hormone Monitor firmware and its companion Android app, made by Quanovate Tech Inc. (operating as Mira/Mira Care). The flaws carry a severity score of 9.8 out of 10, indicating they are critical.
The issues stem from weaknesses including missing authentication for key functions, hard-coded credentials, weak authentication controls, and improper restrictions elsewhere in the system. If exploited, attackers could gain unauthorised access to sensitive health profile information, alter that data, take over user accounts, expose session tokens, or cause the device or app to stop working properly.
While this advisory concerns a consumer health device rather than typical business IT infrastructure, it's a reminder that any connected device handling personal data—including wellness and health tech used by staff—can introduce risk if not properly secured. Businesses that supply, recommend, or integrate connected health devices for employees or customers should watch for vendor updates and apply them promptly.