PT-2026-70925 · Unknown · Mira Cloud Api

CVE-2026-64934

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mira cloud API (affected versions not specified)
Description The Mira cloud API relies on the firmware version reported by the companion app as authoritative for a device without independently verifying the version from the device itself. An authenticated attacker can submit arbitrary firmware version strings for their own device. This allows the attacker to evade vendor-side vulnerable-fleet analytics, suppress security update prompts shown to the user, and misrepresent patch-adoption metrics.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64934

Affected Products

Mira Cloud Api