← Back to Feed

Flow Neuroscience FL-100

CVE-2026-18164

August 13, 2026 · CISA (US-CERT) · Severity: CRITICAL

An undocumented hard-coded credential (CVE-2026-18164) in Flow Neuroscience FL-100 and Halo Neuroscience FL-100 devices permits Bluetooth attackers to manipulate brain stimulation parameters and override safety limits. All firmware versions before July 2026 are affected. Users must update through the Flow app to mitigate the risk.

Key Takeaways

  • Hard-coded credentials shared across all devices allow Bluetooth attackers to bypass authentication.
  • Vulnerable devices can have brain stimulation parameters altered and safety limits overridden.
  • Firmware updates via Flow app are required; users should install the latest version.
☕ Buy a Coffee