Pulsetto Nerve Stimulator Has Hidden BLE Commands
Pulsetto's Vagus Nerve Stimulator accepts undocumented, unauthenticated Bluetooth commands that could disable safety mechanisms or alter stimulation output.
CISA published an ICS medical advisory disclosing CVE-2026-18844, a hidden-functionality flaw (CWE-912) in all versions of the Pulsetto Vagus Nerve Stimulator, a Lithuanian-made wearable device sold worldwide. The device's firmware accepts several undisclosed commands over its Bluetooth Low Energy interface without any authentication or encryption. These commands are never sent by the legitimate companion mobile app but are fully processed by the device whenever it is powered on, meaning any nearby attacker capable of communicating over BLE could potentially disable electrical safety mechanisms or modify stimulation output settings.
The vulnerability was reported to CISA by researcher A.C. Buglione. Pulsetto has not responded to CISA's outreach to coordinate remediation, so no patch or mitigation from the vendor is currently available; affected users are directed to contact Pulsetto support directly. CISA notes the flaw is not exploitable remotely (BLE proximity is required) and no known public exploitation has been reported at this time.
Given the lack of remote exploitability, absence of observed exploitation, and vendor non-responsiveness rather than a broader campaign, this is an informational disclosure rather than an active threat. However, the potential physical-safety impact on a medical device — bypassing safety cutoffs on a nerve-stimulation device — warrants awareness among users and healthcare device administrators.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free