# Pulsetto Nerve Stimulator Has Hidden BLE Commands

Published: 2026-08-11 · Severity: routine · Sectors: healthcare
Canonical: https://vorant.io/reports/29b2fb1a-1ac9-502b-ad3a-eafc84991a01/pulsetto-nerve-stimulator-has-hidden-ble-commands

> Pulsetto's Vagus Nerve Stimulator accepts undocumented, unauthenticated Bluetooth commands that could disable safety mechanisms or alter stimulation output.

CISA published an ICS medical advisory disclosing CVE-2026-18844, a hidden-functionality flaw (CWE-912) in all versions of the Pulsetto Vagus Nerve Stimulator, a Lithuanian-made wearable device sold worldwide. The device's firmware accepts several undisclosed commands over its Bluetooth Low Energy interface without any authentication or encryption. These commands are never sent by the legitimate companion mobile app but are fully processed by the device whenever it is powered on, meaning any nearby attacker capable of communicating over BLE could potentially disable electrical safety mechanisms or modify stimulation output settings.

The vulnerability was reported to CISA by researcher A.C. Buglione. Pulsetto has not responded to CISA's outreach to coordinate remediation, so no patch or mitigation from the vendor is currently available; affected users are directed to contact Pulsetto support directly. CISA notes the flaw is not exploitable remotely (BLE proximity is required) and no known public exploitation has been reported at this time.

Given the lack of remote exploitability, absence of observed exploitation, and vendor non-responsiveness rather than a broader campaign, this is an informational disclosure rather than an active threat. However, the potential physical-safety impact on a medical device — bypassing safety cutoffs on a nerve-stimulation device — warrants awareness among users and healthcare device administrators.

## Mentioned in this report

- Vulnerabilities: CVE-2026-18844

Source reporting: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/29b2fb1a-1ac9-502b-ad3a-eafc84991a01/pulsetto-nerve-stimulator-has-hidden-ble-commands.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
