# Flow Neuroscience FL-100 has hard-coded credential flaw

Published: 2026-08-13 · Severity: routine · Sectors: healthcare
Canonical: https://vorant.io/reports/893e0418-5a67-5ea5-92da-67fbc540eaf0/flow-neuroscience-fl-100-has-hard-coded-credential-flaw

> A hard-coded credential in Flow Neuroscience FL-100 brain-stimulation devices lets nearby attackers bypass authentication via Bluetooth and alter stimulation settings.

CISA has published an ICS Medical Advisory for the Flow Neuroscience FL-100 (also sold as Halo Neuroscience FL-100), a transcranial direct current stimulation device. The flaw, tracked as CVE-2026-18164 and classified under CWE-798, stems from an undocumented hard-coded credential shared across all device units that authorizes bypass of authentication. An attacker within Bluetooth range could exploit this to arbitrarily manipulate brain stimulation parameters and override built-in safety limits, posing a direct physical safety risk to patients using the device.

The vulnerability is not remotely exploitable and requires physical proximity within Bluetooth range, limiting the attack surface to close-proximity scenarios. CISA states no known public exploitation has been reported at this time. The affected products are deployed worldwide, with the manufacturer headquartered in Sweden, and the advisory falls under the Healthcare and Public Health critical infrastructure sector.

Flow Neuroscience has released firmware updates to remediate the issue, distributed via the Flow companion app, and users are encouraged to update immediately. CISA's standard ICS mitigation guidance (network isolation, avoiding internet exposure, VPN use with caution, and phishing awareness) is provided as general defense-in-depth advice, though the Bluetooth-proximity nature of this specific flaw limits the relevance of network-based mitigations.

## Mentioned in this report

- Vulnerabilities: CVE-2026-18164

Source reporting: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-225-01

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/893e0418-5a67-5ea5-92da-67fbc540eaf0/flow-neuroscience-fl-100-has-hard-coded-credential-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
