โ† Back to Feed

Pulsetto Vagus Nerve Stimulator

CVE-2026-18844

August 11, 2026 ยท CISA (US-CERT) ยท Severity: CRITICAL

The Pulsetto Vagus Nerve Stimulator contains a critical vulnerability (CVE-2026-18844) in its firmware, allowing unauthenticated attackers to send hidden commands over Bluetooth Low Energy (BLE). These commands can disable safety features or modify stimulation settings, posing a direct risk to user safety. The vendor has not yet provided mitigations, leaving devices worldwide exposed to potential exploitation. ๐Ÿ“Œ **Analyst Note:** Organizations using this device should isolate it from untrusted networks until a firmware update is released.

Key Takeaways

  • The Pulsetto Vagus Nerve Stimulator has hidden commands in its firmware that can be exploited via BLE.
  • Attackers can disable safety mechanisms or alter stimulation settings without authentication.
  • All versions of the device are affected, with no vendor-provided mitigation yet available.
  • CISA recommends users contact Pulsetto directly for assistance due to lack of vendor engagement.
โ˜• Buy a Coffee