Junglewise Threat Intelligence

CVE-2026-85104: Sooma 2GEN brain stimulator unauthenticated parameter modification via Bluetooth

CVE-2026-85104 · Severity: info · Published 2026-09-16

Executive brief

The Sooma 2GEN is a medical device used for transcranial direct current stimulation therapy. An attacker within Bluetooth range can modify critical stimulation parameters without authentication, potentially altering treatment settings in ways that could harm a patient or compromise the effectiveness of therapy.

Technical details

This vulnerability is an authentication bypass in the Bluetooth interface of the Sooma 2GEN brain stimulator. The device fails to validate the source or authenticate commands received over Bluetooth, allowing an unauthenticated attacker within wireless range to send arbitrary commands to modify brain stimulation parameters. The attack requires no user interaction or prior authentication. An attacker can change stimulation intensity, duration, electrode configuration, or other critical parameters, potentially causing harm to the patient or rendering the device unsafe to use. Patch availability has not been confirmed.

Affected products

  • Sooma 2GEN brain stimulator <UNKNOWN>

Timeline

  • 2026-09-16: disclosed

References