highOther

Flow Neuroscience FL-100 Hard-coded Bluetooth Credential Vulnerability

First seen Aug 16, 2026 · Updated Aug 16, 2026 · CVSS 8.1

ICSmedical-devicehardcoded-credentialsbluetoothCWE-798healthcareIoT

Flow Neuroscience FL-100 (and rebranded Halo Neuroscience FL-100) tDCS devices contain an undocumented hard-coded credential shared across all units, allowing any attacker within Bluetooth range to bypass authentication. Exploitation could let an attacker arbitrarily manipulate brain stimulation parameters and override built-in safety limits, posing direct physical harm risk to patients.

Technical Analysis

CVE-2026-18164 (CVSS v3.1 8.1, CVSS v4.0 7.2) is a Use of Hard-coded Credentials (CWE-798) flaw in the FL-100 firmware prior to July 2026. The device accepts a static, universal authentication credential over Bluetooth Low Energy, enabling an adjacency-range attacker (AV:A, no privileges, no user interaction required) to bypass authentication and issue arbitrary stimulation commands, affecting integrity and availability of the therapeutic function without impacting confidentiality. The vulnerability is not remotely exploitable over the internet and requires physical Bluetooth proximity to the device. This is a medical/consumer IoT device advisory with no direct relevance to AI agent, LLM, or RAG infrastructure, and no agent-impact pathway is present in this disclosure.

Affected Systems

Flow Neuroscience FL-100 firmware versions prior to July 2026; Halo Neuroscience FL-100 (rebranded product) firmware versions prior to July 2026. Devices communicate via Bluetooth and are controlled through the Flow companion app.

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) published; vulnerability is a design flaw (hard-coded credential) rather than an active malware campaign.

Remediation Steps

  1. 1

    Apply Firmware Update

    Install the latest firmware update released by Flow Neuroscience via the Flow companion app to remove the hard-coded credential.

  2. 2

    Restrict Bluetooth Exposure

    Limit physical proximity access to devices and avoid pairing/operating in uncontrolled public spaces where Bluetooth range attacks are feasible.

  3. 3

    Network Isolation

    Where applicable, isolate control system and companion app devices from untrusted networks and follow CISA ICS defense-in-depth guidance.

  4. 4

    Monitor Vendor Advisories

    Track Flow Neuroscience and CISA ICS-MA advisories for further patches or updated mitigation guidance.

CVE / Advisory IDs

CVE-2026-18164

Industries Most Exposed

Healthcare and Public HealthMedical DevicesConsumer Health Technology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.