PT-2026-70925 · Unknown · Mira Cloud Api
CVE-2026-64934
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mira cloud API (affected versions not specified)
Description
The Mira cloud API relies on the firmware version reported by the companion app as authoritative for a device without independently verifying the version from the device itself. An authenticated attacker can submit arbitrary firmware version strings for their own device. This allows the attacker to evade vendor-side vulnerable-fleet analytics, suppress security update prompts shown to the user, and misrepresent patch-adoption metrics.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mira Cloud Api