VYPR
advisoryPublished Aug 11, 2026· 1 source

CISA Warns of Critical Flaws in Pulsetto Vagus Nerve Stimulator

CISA has issued a critical alert regarding the Pulsetto Vagus Nerve Stimulator, warning of hidden commands that could disable safety features or alter treatment settings.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical vulnerability affecting all versions of the Pulsetto Vagus Nerve Stimulator. The flaw, designated CVE-2026-18844, allows attackers to exploit hidden commands transmitted over unauthenticated and unencrypted Bluetooth Low Energy (BLE) connections.

These undisclosed commands, which are not issued by the official Pulsetto mobile application, can be processed by the device when powered on. Successful exploitation could enable an attacker to disable essential electrical safety mechanisms or modify the device's stimulation output settings. This poses a significant risk to patient safety, as it could lead to unintended or harmful therapeutic interventions.

The vulnerability carries a CVSS v3.1 base score of 8.1, classifying it as HIGH severity. The attack vector is adjacent (AV:A), meaning the attacker needs to be in close proximity to the device to exploit the BLE connection. The attack complexity is low (AC:L), with no privileges required (PR:N) and no user interaction needed (UI:N). The impact on confidentiality, integrity, and availability is rated as high (C:N/I:H/A:H).

Pulsetto, the manufacturer based in Lithuania, has not yet provided a response or mitigation strategy to CISA's requests for collaboration. Users of the Pulsetto Vagus Nerve Stimulator are strongly advised to contact the vendor directly at [email protected] for assistance and information regarding potential workarounds or future patches.

CISA recommends that users minimize network exposure for all control system devices, ensuring they are not accessible from the internet. Networks should be protected by firewalls and isolated from business networks. When remote access is necessary, more secure methods like VPNs should be employed, ensuring they are kept updated.

While there are no known public reports of exploitation targeting this specific vulnerability at this time, its nature means it is not remotely exploitable, requiring physical proximity for an attack. The potential for misuse in a healthcare setting underscores the importance of securing medical devices.

This advisory highlights a broader trend of vulnerabilities being discovered in Internet of Medical Things (IoMT) devices, which often lack robust security features. The healthcare sector, in particular, must prioritize the security of connected medical equipment to protect patient data and ensure the integrity of treatment delivery.

Organizations are encouraged to perform thorough impact analyses and risk assessments before implementing any defensive measures. CISA also provides resources on its ICS webpage, including best practices for Industrial Control Systems cybersecurity and targeted cyber intrusion detection and mitigation strategies, which can be adapted for medical device security.

Synthesized by Vypr AI