All stories
highDefensive GuidanceCVE-2026-18844

Unauthenticated attackers can remotely control Pulsetto Vagus Nerve Stimulators via Bluetooth BLE vulnerabilities

⚠️ High severity. An unauthenticated attacker can send undisclosed commands to the Pulsetto Vagus Nerve Stimulator via Bluetooth Low Energy (BLE). This vulnerability allows for unauthorized device control without any encryption or authentication requirements. Ensure your device firmware is up to date and monitor for unexpected connectivity behavior.

Summary

The Pulsetto Vagus Nerve Stimulator contains a critical vulnerability in its firmware that permits the execution of undisclosed commands over a Bluetooth Low Energy (BLE) interface. These commands are processed by the device whenever it is powered on, regardless of whether they originate from the official companion mobile application.

Because the device lacks authentication and encryption for these specific command sets, any nearby actor with a BLE-capable device can interact directly with the hardware. The vulnerability carries a CVSS score of 7.2, reflecting high impact on both integrity and availability.

Technical details

The flaw resides in how the device firmware handles incoming BLE traffic. The Stimulator accepts several undisclosed commands that are never issued by its legitimate companion mobile application.

When the device is powered on, it listens for these specific command structures. Because there is no mechanism to verify the identity of the sender or encrypt the communication channel for these instructions, the hardware processes them as valid inputs. This lack of access control allows an attacker to bypass the intended user interface and mobile app entirely.

Why this matters for defenders

For users and healthcare providers managing these devices, the risk involves unauthorized manipulation of a medical tool. Since the commands are processed without authentication, an attacker does not need to pair with the device or have access to the user's smartphone to influence its operation.

The vulnerability is highly accessible due to the nature of Bluetooth Low Energy, which can be targeted by any nearby actor within radio range. The absence of encryption means that even if a user is actively using the companion app, an attacker could potentially inject commands into the device stream.

Defender guidance

Immediate action should focus on firmware management and environmental awareness:

  • Check for available firmware updates via the official Pulsetto mobile application to ensure any disclosed patches are applied.
  • Minimize the time the device remains in a powered-on state when not actively in use to reduce the window of exposure.
  • Be aware that because these commands are processed upon power-on, the device is vulnerable even before a formal pairing process is completed with a legitimate mobile device.

Sources

  1. https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02
  2. https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-223-02.json
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -