Security & Threat Intelligence · 13.08.2026, 16:55 UTC
Flow Neuroscience FL-100
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories ↗ |
| Veröffentlicht | 13.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-18164. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits. The following versions of Flow Neuroscience FL-100 are affected:
Flow Neuroscience FL-100 Halo Neuroscience FL-100
CVSS Vendor Equipment Vulnerabilities
v3 8.1 Flow Neuroscience Flow Neuroscience FL-100 Use of Hard-coded Credentials
Background
Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: Sweden
Vulnerabilities
Expand All +
CVE-2026-18164
An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarilymanipulate brain stimulation parameters and state. View CVE Details
Affected Products Flow Neuroscience FL-100
Vendor:Flow Neuroscience Product Version:Flow Neuroscience Flow Neuroscience FL-100: <July_2026, Flow Neuroscience Halo Neuroscience FL-100: <July_2026 Product Status:known_affected
Remediations MitigationUsers are encouraged to install the latest firmware updates provided by Flow Neuroscience via the Flow app.
Relevant CWE: CWE-798 Use of Hard-coded Credentials
Metrics
CVSS Version Base Score Base Severity Vector String
3.1 8.1 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
4.0 7.2 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Acknowledgments
A.C. Buglione reported this vulnerability to CISA
Legal Notice and Terms of Use This product is provided subject to …