The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Pulsetto has not responded to requests to work with CISA to mitigate this vulnerability. Users are encouraged to reach out directly to Pulsetto for assistance at [email protected] mailto:[email protected] .


Workaround

No workaround given by the vendor.

History

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.
Title Pulsetto Vagus Nerve Stimulator Hidden Functionality
Weaknesses CWE-912
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-11T20:13:58.827Z

Reserved: 2026-08-04T14:51:10.448Z

Link: CVE-2026-18844

cve-icon Vulnrichment

Updated: 2026-08-11T20:13:54.735Z

cve-icon NVD

Status : Received

Published: 2026-08-11T20:17:37.277

Modified: 2026-08-11T21:17:34.160

Link: CVE-2026-18844

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses