As cited
Copy frozen at (site build).
vulnerabilities
Pulsetto Vagus Nerve Stimulator
The Pulsetto Vagus Nerve Stimulator firmware accepts undisclosed commands over its Bluetooth Low Energy interface without authentication or encryption, allowing an attacker to disable electrical safety mechanisms or modify stimulation settings (CVE-2026-18844, CVSS 8.1). All versions of the device are affected, and the vendor has not responded to requests from CISA to develop a fix. The vulnerability requires local proximity and cannot be exploited remotely.
Why it matters: Healthcare providers and patients using Pulsetto vagus nerve stimulators face a high-severity risk that someone nearby could disable safety features or alter therapy settings without the user's knowledge or consent; contact the vendor immediately for guidance since no patch is available.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Pulsetto Vagus Nerve Stimulator
CVE-2026-18844 affects all versions of the Pulsetto Vagus Nerve Stimulator, a medical device used globally. The vulnerability resides in undisclosed Bluetooth Low Energy (BLE) commands sent without authentication or encryption that allow attackers to disable safety mechanisms or alter stimulation settings. Pulsetto has not engaged with CISA on remediation, and users are directed to contact the vendor directly for assistance.
Why it matters: Medical device operators and patients using Pulsetto stimulators face direct risk of unauthorized device manipulation; immediate vendor contact for patched firmware is necessary to prevent malicious modification of therapy output.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Pulsetto Vagus Nerve Stimulator
CVE-2026-18844 affects all versions of the Pulsetto Vagus Nerve Stimulator, a medical device used globally. The vulnerability resides in undisclosed Bluetooth Low Energy (BLE) commands sent without authentication or encryption that allow attackers to disable safety mechanisms or alter stimulation settings. Pulsetto has not engaged with CISA on remediation, and users are directed to contact the vendor directly for assistance.
Why it matters: Medical device operators and patients using Pulsetto stimulators face direct risk of unauthorized device manipulation; immediate vendor contact for patched firmware is necessary to prevent malicious modification of therapy output.
- Source published
- First seen by Cybersecurity Tracker