Junglewise Threat Intelligence

CVE-2026-2671: Mendi Neurofeedback Headset V4 cleartext transmission in Bluetooth Low Energy Handler

CVE-2026-2671 · Severity: low · CVSS 3.1 · Published 2026-03-07

Executive brief

The Mendi Neurofeedback Headset V4 is a wearable device used for real-time brain activity monitoring and cognitive training. A vulnerability in its Bluetooth Low Energy communication handler allows sensitive information to be transmitted without encryption, potentially exposing user health and biometric data to attackers on the local network.

Technical details

The vulnerability involves cleartext transmission of sensitive information through the Bluetooth Low Energy (BLE) Handler component in the Mendi Neurofeedback Headset V4. The attack vector is limited to adjacent/local network range, requiring the attacker to be within Bluetooth proximity. Attack complexity is rated as high and exploitation is considered difficult, suggesting additional preconditions or specific circumstances are necessary. An attacker within BLE range could intercept and read unencrypted sensitive data transmitted by the device. Patches or mitigations are not documented in available public sources; the vendor did not respond to early disclosure notifications.

Affected products

  • Mendi Neurofeedback Headset V4 V4

Timeline

  • 2026-03-07: disclosed

References