Executive brief
The Pulsetto Vagus Nerve Stimulator is a medical device that uses electrical stimulation to treat neurological conditions. The device's firmware accepts undisclosed commands over Bluetooth without authentication or encryption, allowing an attacker within Bluetooth range to disable safety mechanisms or alter stimulation output, potentially causing harm to patients.
Technical details
The vulnerability is a hidden functionality issue (CWE-912) in the device's Bluetooth Low Energy (BLE) interface. The firmware accepts several undisclosed commands that are not issued by the legitimate companion mobile application, but are fully processed when the device is powered on. These commands are sent without any authentication or encryption protection. An attacker with Bluetooth proximity can exploit this to modify stimulation output settings or disable electrical safety mechanisms. No patch is currently available; the vendor has not responded to CISA mitigation requests.
Affected products
- Pulsetto Vagus Nerve Stimulator all
Timeline
- 2026-08-11: disclosed
- 2026-08-11: advisory: CISA ICSMA-26-223-02