Project Subscriptions
No data.
No advisories yet.
Solution
Pulsetto has not responded to requests to work with CISA to mitigate this vulnerability. Users are encouraged to reach out directly to Pulsetto for assistance at [email protected] mailto:[email protected] .
Workaround
No workaround given by the vendor.
Tue, 11 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on. | |
| Title | Pulsetto Vagus Nerve Stimulator Hidden Functionality | |
| Weaknesses | CWE-912 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-11T20:13:58.827Z
Reserved: 2026-08-04T14:51:10.448Z
Link: CVE-2026-18844
Updated: 2026-08-11T20:13:54.735Z
Status : Received
Published: 2026-08-11T20:17:37.277
Modified: 2026-08-11T21:17:34.160
Link: CVE-2026-18844
No data.
OpenCVE Enrichment
No data.