Vulnerabilities have been identified in two consumer health and wellness devices – The Mira Hormone Monitor, a popular fertility tracking device, and the Pulsetto Vagus Nerve Stimulator. Vulnerabilities in the former could result in sensitive data exposure and data manipulation. The latter has a vulnerability that poses a safety risk to users.
Mira Hormone Monitor & Mira Android App Multiple vulnerabilities have been identified in the Mira Hormone Monitor and its associated Android app that could expose sensitive health data, cause a denial-of-service condition, and allow an unauthorized individual to take control of user accounts and manipulate data, potentially resulting in failed fertility treatments, missed fertility windows, or unwanted pregnancies.
The vulnerabilities were identified by a team of researchers at Northeastern University SPQR Lab. The research was partly funded by the Department of Health and Human Services’ Advanced Research Projects Agency for Health (ARPA-H) through a grant issued under the Universal Patching and Remediation for Autonomous Defense program. The vulnerabilities were reported to the device manufacturer, Quanovate Tech, which has taken steps to address the vulnerabilities.
The researchers conducted a full-chain security assessment of the Mira Ultra 5 fertility hormone analyzer and associated Android app and cloud infrastructure. The researchers identified 20 vulnerabilities in the device, app, and cloud infrastructure, including two critical vulnerabilities. The most serious vulnerabilities could be exploited by an attacker to gain read and write access to reproductive health profiles, resulting in forgery, deletion, or destruction of health information, and to gain control of cloud accounts and access hormone record information and account settings.
Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy Key Vulnerabilities The vulnerabilities include weak or missing authentication, transmission of user data to third parties through analytics code and SDKs, hard-coded API keys, a lack of rate-limiting/IP-throttling, and publicly accessible firmware.
The vulnerabilities affect Mira Monitor Firmware 1. 7. 1.
47 and Mira Android App 4. 5. 15.
- Vulnerability CVSS v3. 1 Base Score CVSS v4.
0 Base Score Outcome of Successful Exploitation CVE-2026-68067 9. 8 (Critical) 9. 8 (Critical) Gain control of cloud accounts and access hormone record information and account settings.
CVE-2026-67568 9. 1 (Critical) 9. 3 (Critical) Gain read and write access to reproductive health profiles, resulting in forgery, deletion, or destruction of health information.
CVE-2026-66875 8. 8 (High) 8. 7 (High) Extract stored hormone measurements; denial-of-service; passively track the user.
CVE-2026-67558 7. 4 (High) 8. 2 (High) Capture live session token information; inject forged hormone measurements into the victim’s cloud record and clinical trend view.
CVE-2026-66098 6. 5 (Medium) 7. 1 (High) Denial-of-service; disrupt ovulation tracking and fertility monitoring workflow.
CVE-2026-66832 6. 5 (Medium) 6. 9 (Medium) Obtain live session token.
CVE-2026-66340 5. 3 (Medium) 6. 9 (Medium) Brute force access to user account CVE-2026-64934 4.
3 (Medium) 5. 3 (Medium) Submission of arbitrary firmware version strings for their own device; evade vendor-side vulnerable-fleet analytics; suppress security update prompts to the user; misrepresent patch-adoption metrics. The researchers coordinated with the device manufacturer and CISA and previewed the findings after Quanovate had completed two rounds of remediation.
Quanovate has released updates to fix these vulnerabilities, and users should upgrade to the latest firmware/app versions: iOS v3. 5. 18 / Android v4.
- Firmware v01.
- 53 is updated via the app when the device is connected.
No evidence has been found of any actual or attempted exploitation of the vulnerabilities. Pulsetto Vagus Nerve Stimulator A high-severity vulnerability has been identified in the firmware of the Pulsetto Vagus Nerve Stimulator. Successful exploitation could allow an attacker to disable electrical safety mechanisms or modify other stimulation output settings.
The issue is due to the firmware accepting hidden commands over its Bluetooth Low Energy (BLE) interface. The commands are sent without authorization or encryption and are never issued by the companion mobile application; however, they are fully processed when the device is powered on. The vulnerability is tracked as CVE-2026-18844 and affects all current versions.
The vulnerability has been assigned a CVSS v3. 1 base score of 8. 1, and a v4.
0 base score of 7. 2. The vulnerability was identified by researcher and security author A.
C. Buglione, who reported the vulnerability to CISA. CISA reached out to Pulsetto regarding the vulnerability but did not receive a response.
CISA has therefore advised users to contact Pulsetto directly for information on how the issue can be remediated. The post Critical Vulnerabilities Identified in Popular Consumer Fertility Device appeared first on The HIPAA Journal .
Originally published at hipaajournal.com

