Flow Neuroscience FL-100 Hard-coded Bluetooth Credential Vulnerability
First seen Aug 16, 2026 · Updated Aug 16, 2026 · CVSS 8.1
Flow Neuroscience FL-100 (and rebranded Halo Neuroscience FL-100) tDCS devices contain an undocumented hard-coded credential shared across all units, allowing any attacker within Bluetooth range to bypass authentication. Exploitation could let an attacker arbitrarily manipulate brain stimulation parameters and override built-in safety limits, posing direct physical harm risk to patients.
Technical Analysis
CVE-2026-18164 (CVSS v3.1 8.1, CVSS v4.0 7.2) is a Use of Hard-coded Credentials (CWE-798) flaw in the FL-100 firmware prior to July 2026. The device accepts a static, universal authentication credential over Bluetooth Low Energy, enabling an adjacency-range attacker (AV:A, no privileges, no user interaction required) to bypass authentication and issue arbitrary stimulation commands, affecting integrity and availability of the therapeutic function without impacting confidentiality. The vulnerability is not remotely exploitable over the internet and requires physical Bluetooth proximity to the device. This is a medical/consumer IoT device advisory with no direct relevance to AI agent, LLM, or RAG infrastructure, and no agent-impact pathway is present in this disclosure.
Affected Systems
Flow Neuroscience FL-100 firmware versions prior to July 2026; Halo Neuroscience FL-100 (rebranded product) firmware versions prior to July 2026. Devices communicate via Bluetooth and are controlled through the Flow companion app.
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) published; vulnerability is a design flaw (hard-coded credential) rather than an active malware campaign.
Remediation Steps
- 1
Apply Firmware Update
Install the latest firmware update released by Flow Neuroscience via the Flow companion app to remove the hard-coded credential.
- 2
Restrict Bluetooth Exposure
Limit physical proximity access to devices and avoid pairing/operating in uncontrolled public spaces where Bluetooth range attacks are feasible.
- 3
Network Isolation
Where applicable, isolate control system and companion app devices from untrusted networks and follow CISA ICS defense-in-depth guidance.
- 4
Monitor Vendor Advisories
Track Flow Neuroscience and CISA ICS-MA advisories for further patches or updated mitigation guidance.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.