Executive brief
The Flow Neuroscience FL-100 is a brain stimulation device used for therapeutic purposes. An attacker within Bluetooth range can use an undocumented hard-coded credential shared across all units to bypass authentication and arbitrarily modify stimulation parameters and safety settings, potentially causing harm to patients.
Technical details
The vulnerability is a hard-coded credential (CWE-798) embedded in the device firmware that is shared across all FL-100 units. An attacker within Bluetooth range can use this credential to authenticate without authorization, granting them access to modify brain stimulation parameters and override safety limits. No user interaction or prior authentication is required; the vulnerability is triggered purely by proximity. The attack vector is adjacent (Bluetooth range). Firmware updates provided via the Flow app are available to remediate the issue.
Affected products
- Flow Neuroscience FL-100 before July 2026
Timeline
- 2026-08-13: disclosed