Flow Neuroscience FL-100 has hard-coded credential flaw
A hard-coded credential in Flow Neuroscience FL-100 brain-stimulation devices lets nearby attackers bypass authentication via Bluetooth and alter stimulation settings.
CISA has published an ICS Medical Advisory for the Flow Neuroscience FL-100 (also sold as Halo Neuroscience FL-100), a transcranial direct current stimulation device. The flaw, tracked as CVE-2026-18164 and classified under CWE-798, stems from an undocumented hard-coded credential shared across all device units that authorizes bypass of authentication. An attacker within Bluetooth range could exploit this to arbitrarily manipulate brain stimulation parameters and override built-in safety limits, posing a direct physical safety risk to patients using the device.
The vulnerability is not remotely exploitable and requires physical proximity within Bluetooth range, limiting the attack surface to close-proximity scenarios. CISA states no known public exploitation has been reported at this time. The affected products are deployed worldwide, with the manufacturer headquartered in Sweden, and the advisory falls under the Healthcare and Public Health critical infrastructure sector.
Flow Neuroscience has released firmware updates to remediate the issue, distributed via the Flow companion app, and users are encouraged to update immediately. CISA's standard ICS mitigation guidance (network isolation, avoiding internet exposure, VPN use with caution, and phishing awareness) is provided as general defense-in-depth advice, though the Bluetooth-proximity nature of this specific flaw limits the relevance of network-based mitigations.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-225-01
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free