CISA Warns of Hard-Coded Credential Vulnerability in Flow Neuroscience Devices
CISA has issued an advisory for a critical vulnerability in Flow Neuroscience FL-100 and Halo Neuroscience FL-100 devices, allowing attackers within Bluetooth range to bypass authentication and manipulate stimulation parameters.

CISA has released an advisory detailing a critical security flaw affecting Flow Neuroscience's FL-100 and Halo Neuroscience FL-100 devices. The vulnerability, identified as CVE-2026-18164, stems from the use of a hard-coded credential that is present across all device units.
This hard-coded credential allows an attacker who is within Bluetooth range of an affected device to bypass the normal authentication mechanisms. Once authenticated, the attacker can arbitrarily manipulate the brain stimulation parameters and alter the device's state. This could lead to overriding safety limits, potentially posing a risk to users.
The vulnerability is classified with a CVSS v3.1 base score of 8.1, earning it a 'HIGH' severity rating. The CVSS vector string (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) indicates that while the attack requires proximity (Attack Vector: Adjacent), it has low complexity, requires no privileges, and has no user interaction. The impact on confidentiality is none, but the impact on integrity and availability is high.
Flow Neuroscience's FL-100 and Halo Neuroscience FL-100 devices are affected if their firmware version is prior to July 2026. The company has acknowledged the vulnerability and provided a remediation path.
To address this issue, users are strongly advised to update the firmware on their devices. Flow Neuroscience provides these updates through the Flow app. Applying the latest firmware is crucial to patch the vulnerability and restore the intended security posture of the devices.
While no known public exploitation targeting this specific vulnerability has been reported to CISA at this time, the advisory emphasizes the importance of proactive security measures. The vulnerability is not remotely exploitable, meaning an attacker must be physically close to the device and within Bluetooth range.
CISA recommends general defensive measures for control system devices, including minimizing network exposure, locating devices behind firewalls, and using secure remote access methods like VPNs. Organizations are encouraged to perform impact analyses and risk assessments before deploying any defensive measures.
This advisory highlights the ongoing security challenges in the medical device sector, where vulnerabilities in connected devices can have direct implications for patient safety. The use of hard-coded credentials remains a persistent and dangerous security weakness that manufacturers must diligently address.