Description
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.
Published: 2026-08-11
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Pulsetto’s firmware accepts a set of hidden commands over its Bluetooth Low Energy interface. The commands are transmitted without authentication or encryption and are not issued by the legitimate companion mobile application. When the device is powered on, it processes these commands, providing an attacker with the ability to alter its operational behavior. This flaw corresponds to CWE‑912, indicating a hard‑coded, undisclosed channel for remote command execution that can compromise device integrity and patient safety.

Affected Systems

The vulnerability affects Pulsetto Vagus Nerve Stimulators. No specific firmware or hardware version information is provided in the CNA data, so all models manufactured by Pulsetto are assumed to be susceptible.

Risk and Exploitability

The CVSS score of 7.2 indicates a moderate severity, while the EPSS score of less than 1% reflects a low likelihood of exploitation. The device is not listed in the CISA KEV catalog. The attack vector is inferred to require proximity to the device, enabling an attacker to establish a BLE connection while the stimulator is powered on and transmit the hidden commands without needing credentials or encryption. Successful exploitation could lead to unauthorized alteration of therapy settings or device disruption, adversely affecting the patient’s health.

Generated by OpenCVE AI on August 12, 2026 at 19:40 UTC.

Remediation

Vendor Solution

Pulsetto has not responded to requests to work with CISA to mitigate this vulnerability. Users are encouraged to reach out directly to Pulsetto for assistance at info@pulsetto.tech mailto:info@pulsetto.tech .


OpenCVE Recommended Actions

  • Contact Pulsetto directly at info@pulsetto.tech to request a firmware update or patch for the affected Vagus Nerve Stimulator.
  • Ensure that the device is only powered on and used within a trusted environment, preferably while connected through the official companion application which normally does not issue the hidden commands.
  • Implement physical security measures to prevent unauthorized access or proximity of BLE transmitters near the device, reducing the opportunity for an attacker to establish an illicit BLE session.

Generated by OpenCVE AI on August 12, 2026 at 19:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Pulsetto
Pulsetto vagus Nerve Stimulator
Vendors & Products Pulsetto
Pulsetto vagus Nerve Stimulator

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.
Title Pulsetto Vagus Nerve Stimulator Hidden Functionality
Weaknesses CWE-912
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Pulsetto Vagus Nerve Stimulator
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-11T20:13:58.827Z

Reserved: 2026-08-04T14:51:10.448Z

Link: CVE-2026-18844

cve-icon Vulnrichment

Updated: 2026-08-11T20:13:54.735Z

cve-icon NVD

Status : Received

Published: 2026-08-11T20:17:37.277

Modified: 2026-08-11T21:17:34.160

Link: CVE-2026-18844

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:49:17Z

Weaknesses