Impact
An undocumented hard-coded credential shared by all Flow and Halo Neuroscience FL-100 devices bypasses authentication, allowing an attacker to arbitrarily modify brain stimulation parameters and state. The weakness is a credential storage flaw (CWE-798). The impact is loss of device integrity and potential harm to patients.
Affected Systems
The affected products are Flow Neuroscience FL-100 and Halo Neuroscience FL-100 devices. The CVE data does not specify affected firmware versions.
Risk and Exploitability
The CVSS score is 7.2, indicating high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is Bluetooth, inferred from the description that an attacker within Bluetooth range can succeed. Successful exploitation would provide full control over stimulation parameters without user authentication.
OpenCVE Enrichment