Vulnerability in Brain Stimulation Devices by Unnamed Vendor
CVE-2026-18164

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-18164?

An undocumented hard-coded credential present in multiple models of brain stimulation devices allows unauthorized users within Bluetooth range to bypass authentication mechanisms. This vulnerability permits attackers to gain control over brain stimulation parameters and states, potentially leading to severe consequences for patient safety and device integrity.

Affected Version(s)

FL-100 0

FL-100 0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

A.C. Buglione reported this vulnerability to CISA.
.