<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Pulsetto Vagus Nerve Stimulator - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/pulsetto-vagus-nerve-stimulator/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 11 Aug 2026 17:37:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/pulsetto-vagus-nerve-stimulator/feed.xml" rel="self" type="application/rss+xml"/><item><title>Unauthenticated Command Execution in Pulsetto Vagus Nerve Stimulator</title><link>https://feed.craftedsignal.io/briefs/2026-08-pulsetto-vagus-nerve-stimulator/</link><pubDate>Tue, 11 Aug 2026 17:37:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-pulsetto-vagus-nerve-stimulator/</guid><description>The Pulsetto Vagus Nerve Stimulator firmware contains undocumented Bluetooth Low Energy commands that allow an adjacent attacker to bypass safety mechanisms and modify stimulation settings without authentication.</description><content:encoded><![CDATA[<p>CISA has disclosed a high-severity vulnerability, CVE-2026-18844, affecting all versions of the Pulsetto Vagus Nerve Stimulator. The vulnerability stems from hidden functionality within the device firmware, which exposes several undisclosed commands over the Bluetooth Low Energy (BLE) interface. These commands are processed by the device without requiring authentication or encryption, effectively bypassing the security controls implemented by the official companion mobile application. An adjacent attacker within Bluetooth range can issue these commands to disable internal electrical safety mechanisms or arbitrarily modify stimulation output settings, posing a significant safety risk to users. Pulsetto has not yet provided a mitigation or patch for this issue.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance within Bluetooth range of a target Pulsetto Vagus Nerve Stimulator.</li>
<li>Attacker initiates a Bluetooth Low Energy (BLE) connection to the target device.</li>
<li>Attacker identifies the handle or characteristic associated with the device's undocumented firmware command interface.</li>
<li>Attacker crafts a custom payload containing the unauthorized command strings.</li>
<li>Attacker transmits the unauthenticated command over the BLE protocol.</li>
<li>Device firmware receives and processes the unauthorized command without authentication or encryption.</li>
<li>Attacker successfully disables electrical safety mechanisms or alters stimulation output settings to impact the device operation.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The vulnerability directly impacts the Healthcare and Public Health sector, as the device is deployed worldwide for patient care. If exploited, an attacker could manipulate the therapeutic output of the stimulator, potentially causing physical harm by disabling safety mechanisms or delivering unintended levels of nerve stimulation. No known in-the-wild exploitation has been reported to CISA as of the publication date.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for security teams managing or monitoring environments containing these devices:</p>
<ul>
<li>Minimize physical access to areas where these medical devices are in use by patients to reduce the likelihood of an adjacent Bluetooth attack.</li>
<li>Isolate affected medical devices from critical clinical networks to prevent cross-contamination if a compromised device is used as a pivot point, although this vulnerability is currently limited to adjacent BLE access.</li>
<li>Contact the vendor directly at <a href="mailto:info@pulsetto.tech">info@pulsetto.tech</a> to request a firmware update or remediation plan for CVE-2026-18844.</li>
<li>Review site-specific security policies regarding the use of personal medical electronics in controlled facility environments.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>medical-device</category><category>iot</category><category>ble</category><category>cve-2026-18844</category></item></channel></rss>