{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-18844/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Pulsetto Vagus Nerve Stimulator"],"_cs_severities":["high"],"_cs_tags":["medical-device","iot","ble","cve-2026-18844"],"_cs_type":"threat","_cs_vendors":["Pulsetto"],"content_html":"\u003cp\u003eCISA has disclosed a high-severity vulnerability, CVE-2026-18844, affecting all versions of the Pulsetto Vagus Nerve Stimulator. The vulnerability stems from hidden functionality within the device firmware, which exposes several undisclosed commands over the Bluetooth Low Energy (BLE) interface. These commands are processed by the device without requiring authentication or encryption, effectively bypassing the security controls implemented by the official companion mobile application. An adjacent attacker within Bluetooth range can issue these commands to disable internal electrical safety mechanisms or arbitrarily modify stimulation output settings, posing a significant safety risk to users. Pulsetto has not yet provided a mitigation or patch for this issue.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance within Bluetooth range of a target Pulsetto Vagus Nerve Stimulator.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a Bluetooth Low Energy (BLE) connection to the target device.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the handle or characteristic associated with the device's undocumented firmware command interface.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a custom payload containing the unauthorized command strings.\u003c/li\u003e\n\u003cli\u003eAttacker transmits the unauthenticated command over the BLE protocol.\u003c/li\u003e\n\u003cli\u003eDevice firmware receives and processes the unauthorized command without authentication or encryption.\u003c/li\u003e\n\u003cli\u003eAttacker successfully disables electrical safety mechanisms or alters stimulation output settings to impact the device operation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability directly impacts the Healthcare and Public Health sector, as the device is deployed worldwide for patient care. If exploited, an attacker could manipulate the therapeutic output of the stimulator, potentially causing physical harm by disabling safety mechanisms or delivering unintended levels of nerve stimulation. No known in-the-wild exploitation has been reported to CISA as of the publication date.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for security teams managing or monitoring environments containing these devices:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMinimize physical access to areas where these medical devices are in use by patients to reduce the likelihood of an adjacent Bluetooth attack.\u003c/li\u003e\n\u003cli\u003eIsolate affected medical devices from critical clinical networks to prevent cross-contamination if a compromised device is used as a pivot point, although this vulnerability is currently limited to adjacent BLE access.\u003c/li\u003e\n\u003cli\u003eContact the vendor directly at \u003ca href=\"mailto:info@pulsetto.tech\"\u003einfo@pulsetto.tech\u003c/a\u003e to request a firmware update or remediation plan for CVE-2026-18844.\u003c/li\u003e\n\u003cli\u003eReview site-specific security policies regarding the use of personal medical electronics in controlled facility environments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T17:37:10Z","date_published":"2026-08-11T17:37:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-pulsetto-vagus-nerve-stimulator/","summary":"The Pulsetto Vagus Nerve Stimulator firmware contains undocumented Bluetooth Low Energy commands that allow an adjacent attacker to bypass safety mechanisms and modify stimulation settings without authentication.","title":"Unauthenticated Command Execution in Pulsetto Vagus Nerve Stimulator","url":"https://feed.craftedsignal.io/briefs/2026-08-pulsetto-vagus-nerve-stimulator/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-18844","version":"https://jsonfeed.org/version/1.1"}