โ Back to Feed
Pulsetto Vagus Nerve Stimulator
CVE-2026-18844
August 11, 2026 ยท CISA (US-CERT) ยท Severity: CRITICAL
The Pulsetto Vagus Nerve Stimulator contains a critical vulnerability (CVE-2026-18844) in its firmware, allowing unauthenticated attackers to send hidden commands over Bluetooth Low Energy (BLE). These commands can disable safety features or modify stimulation settings, posing a direct risk to user safety. The vendor has not yet provided mitigations, leaving devices worldwide exposed to potential exploitation. ๐ **Analyst Note:** Organizations using this device should isolate it from untrusted networks until a firmware update is released.
Key Takeaways
- The Pulsetto Vagus Nerve Stimulator has hidden commands in its firmware that can be exploited via BLE.
- Attackers can disable safety mechanisms or alter stimulation settings without authentication.
- All versions of the device are affected, with no vendor-provided mitigation yet available.
- CISA recommends users contact Pulsetto directly for assistance due to lack of vendor engagement.