← Back to Feed
Flow Neuroscience FL-100
CVE-2026-18164
August 13, 2026 · CISA (US-CERT) · Severity: CRITICAL
An undocumented hard-coded credential (CVE-2026-18164) in Flow Neuroscience FL-100 and Halo Neuroscience FL-100 devices permits Bluetooth attackers to manipulate brain stimulation parameters and override safety limits. All firmware versions before July 2026 are affected. Users must update through the Flow app to mitigate the risk.
Key Takeaways
- Hard-coded credentials shared across all devices allow Bluetooth attackers to bypass authentication.
- Vulnerable devices can have brain stimulation parameters altered and safety limits overridden.
- Firmware updates via Flow app are required; users should install the latest version.