Impact
An attacker who is within Bluetooth range of a Sooma 2GEN brain stimulator can change stimulation parameters without authentication. This flaw allows a local adversary to alter therapy settings during use, potentially causing harm or ineffective treatment. The weakness is classified as CWE-924, representing improper control of channel or protocol execution, which permits untrusted input to influence critical device behavior.
Affected Systems
The vulnerability applies to the Sooma tDCS Home Therapy brain stimulator produced by Sooma. No specific firmware or version numbers are listed in the publicly available data, so all current models may be affected until an official patch or update is released.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Because authentication is lacking, the attack vector is local Bluetooth; any unauthorized user within range can trigger parameter changes. The mitigations rely on vendor firmware updates or disabling Bluetooth functionality to prevent exploitation.
OpenCVE Enrichment