CVE-2026-64934
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Aug 11, 2026
Vendor
unknown
Description
The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics.