Pulsetto Vagus Nerve Stimulator Hidden Functionality (CWE-912) via BLE
First seen Aug 12, 2026 · Updated Aug 12, 2026 · CVSS 8.1
The Pulsetto Vagus Nerve Stimulator firmware accepts undisclosed, unauthenticated Bluetooth Low Energy commands that are not issued by the official companion app but are still processed by the device. Successful exploitation could allow a nearby attacker to disable electrical safety mechanisms or alter stimulation output settings, posing a physical safety risk to users. The vendor has not responded to CISA's coordination attempts, and no patch is currently available.
Technical Analysis
CVE-2026-18844 is a CWE-912 (Hidden Functionality) flaw in which the device firmware processes undocumented BLE commands sent without authentication or encryption, despite these commands never being generated by the legitimate mobile application. The CVSS v3.1 score is 8.1 (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H), reflecting high integrity and availability impact via adjacent network access with no privileges or user interaction required; CVSS v4.0 scores it 7.2. Exploitation requires BLE proximity to the device rather than remote internet access, and no public exploitation has been reported. This is a consumer/medical IoT hardware vulnerability with no direct relevance to AI agent frameworks, LLM tool use, or RAG pipelines, and no agent-relevant impact is plausible here.
Affected Systems
Pulsetto Vagus Nerve Stimulator, all firmware versions (vers:all/*), manufactured by Pulsetto (Lithuania); deployed worldwide in consumer/healthcare settings
Indicators of Compromise
- None provided - this is a hardware/firmware design flaw, not an active exploitation campaign with known indicators
Remediation Steps
- 1
Restrict BLE proximity exposure
Limit physical/BLE proximity access to the device, as exploitation requires an attacker to be within Bluetooth range.
- 2
Contact vendor directly
Since Pulsetto has not responded to CISA, users should contact Pulsetto support directly at info@pulsetto.tech to request firmware fixes or guidance.
- 3
Monitor for vendor firmware updates
Regularly check for and apply any firmware updates released by Pulsetto that address the hidden BLE command functionality.
- 4
Discontinue use if risk is unacceptable
Given no vendor response and safety-relevant stimulation controls at risk, consider discontinuing device use until a fix is available if the risk is unacceptable to the user.
- 5
Follow general ICS/IoT hardening practices
Apply CISA-recommended practices such as minimizing exposure, network segmentation where applicable, and avoiding social engineering vectors that could facilitate physical device compromise.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.