Description
An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state.
Published: 2026-08-13
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An undocumented hard-coded credential shared by all Flow and Halo Neuroscience FL-100 devices bypasses authentication, allowing an attacker to arbitrarily modify brain stimulation parameters and state. The weakness is a credential storage flaw (CWE-798). The impact is loss of device integrity and potential harm to patients.

Affected Systems

The affected products are Flow Neuroscience FL-100 and Halo Neuroscience FL-100 devices. The CVE data does not specify affected firmware versions.

Risk and Exploitability

The CVSS score is 7.2, indicating high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is Bluetooth, inferred from the description that an attacker within Bluetooth range can succeed. Successful exploitation would provide full control over stimulation parameters without user authentication.

Generated by OpenCVE AI on August 13, 2026 at 21:07 UTC.

Remediation

Vendor Solution

Users are encouraged to install the latest firmware updates provided by Flow Neuroscience via the Flow app.


OpenCVE Recommended Actions

  • Apply the latest firmware updates provided by Flow Neuroscience via the Flow app
  • Restrict or disable the device’s Bluetooth interface until a patch is applied
  • Block or quarantine the device on networks where exposure to unauthorized Bluetooth traffic can be avoided

Generated by OpenCVE AI on August 13, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state.
Title Flow Neuroscience FL-100 Use of Hard-coded Credentials
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-13T19:13:04.494Z

Reserved: 2026-07-28T20:16:40.248Z

Link: CVE-2026-18164

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T20:17:19.440

Modified: 2026-08-13T20:17:19.440

Link: CVE-2026-18164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:15:03Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials