Sceawere

Vulnerability Detail

CVE-2026-18164UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Hard-Coded Credential Authentication Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
Flow Neuroscience
Product
FL-100
Attack Type
CWE-798
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-13T20:17:19.440Z",
  "pubdate": "2026-08-13T20:17:19.440Z",
  "executiveSummary": "An undocumented hard-coded credential vulnerability exists that affects device units utilizing Bluetooth communication interfaces. The vulnerability stems from the implementation of a static, globally shared authentication secret embedded within the device firmware, which authorizes complete bypass of standard authentication mechanisms.\nThe primary impact of this vulnerability is the complete compromise of device integrity and patient safety, as an unauthorized adversary can remotely manipulate critical brain stimulation parameters and operational states.\nThe risk implications are severe due to the medical nature of the affected systems, potentially resulting in adverse physiological effects or unauthorized control over therapeutic neuromodulation treatments.\nTo successfully exploit this vulnerability, an attacker is required to be within physical proximity utilizing the Bluetooth wireless range of the target device unit.\nNo prior authentication credentials, user interaction, or elevated privileges are necessary to execute the exploit, provided the adversary can interface with the vulnerable Bluetooth service and supply the hard-coded bypass token.",
  "technicalDetails": "The root cause of the vulnerability lies in insecure software development practices, specifically the inclusion of a hard-coded cryptographic or plaintext credential that is identical across all manufactured device units. This static credential is explicitly configured within the authentication routines to grant unrestricted access, bypassing standard verification procedures.\nThe vulnerable component is the Bluetooth interface and its associated session establishment or access control handler, which fails to enforce unique, per-device authentication or dynamic challenge-response mechanisms.\nThe attack flow proceeds as follows: First, an attacker within Bluetooth radio range initiates a device discovery and connection sequence targeting the vulnerable unit. Second, upon establishing a wireless link, the attacker interacts with the exposed Bluetooth service responsible for device administration and configuration. Third, rather than providing a dynamically generated, user-specific, or securely negotiated token, the attacker supplies the static, hard-coded credential embedded within the firmware. Fourth, the authentication subsystem validates the supplied secret against the hard-coded value, incorrectly authorizes the session, and grants administrative access.\nOnce authentication is successfully bypassed, the attacker achieves complete control over the device state and core functionalities. The payload behavior involves issuing unauthorized commands via the Bluetooth protocol to arbitrarily modify parameters governing brain stimulation. Post-exploitation impact includes the potential alteration of therapeutic delivery, disruption of normal device operation, or unauthorized monitoring of device status, all without leaving standard authentication logs indicative of a breach."
}
CVE-2026-18164: Hard-Coded Credential Authentication Bypass (HIGH Severity, CVSS: 8.1) - Sceawere