Sceawere
Vulnerability Detail
CVE-2026-18844UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Pulsetto BLE Undocumented Commands Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 6h ago
- Vendor
- Pulsetto
- Product
- Vagus Nerve Stimulator
- Attack Type
- CWE-912
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-08-11T20:17:37.277Z",
"pubdate": "2026-08-11T20:17:37.277Z",
"executiveSummary": "The Pulsetto Vagus Nerve Stimulator firmware contains an authorization and encryption bypass vulnerability within its Bluetooth Low Energy (BLE) interface. The affected product is the Pulsetto Vagus Nerve Stimulator, which processes several undisclosed commands that are never utilized or issued by the official companion mobile application. These administrative or diagnostic commands lack any authentication or encryption mechanisms and are fully accepted and executed by the device whenever it is powered on.\nThe risk implications of this vulnerability are severe due to the physical interaction of the device with the human body via vagus nerve stimulation. An unauthorized attacker within proximity of the device's BLE radio range can interact directly with the hardware interface without requiring prior authentication, pairing procedures, or specialized privileges. By transmitting these undocumented raw BLE commands, a malicious actor can trigger unintended device states, manipulate stimulation parameters, or bypass safety controls implemented by the companion application.\nThe attack requires no prior access or credentials, relying solely on proximity to the physical device and standard BLE scanning and connection capabilities. This exposes users to potential safety hazards and unauthorized physical manipulation through RF exploitation.",
"technicalDetails": "The root cause of this vulnerability lies in the insecure design and implementation of the firmware's Bluetooth Low Energy (BLE) command parsing logic within the Pulsetto Vagus Nerve Stimulator. The vulnerable component is the BLE communication stack and command dispatcher running on the device firmware, which fails to enforce access control lists (ACLs), cryptographic authentication, or message integrity checks for incoming characteristic writes or command frames.\nThe attack flow proceeds as follows. First, an attacker utilizes standard BLE reconnaissance tools (such as hcitool, gatttool, or custom scripts using libraries like BlueZ or PyBluez) to scan for the advertising Pulsetto Vagus Nerve Stimulator device. Once the device is identified and within radio range, the attacker establishes a direct BLE connection. Second, the attacker bypasses the companion mobile application entirely, avoiding any intended abstraction layers or control logic.\nThird, the attacker leverages the lack of authentication and encryption on the BLE interface to transmit raw, undisclosed command byte sequences directly to the device's receptive characteristics. Because the firmware lacks input validation and authorization checks for these hidden routines, the internal command processor interprets and executes the payloads directly upon receipt. These commands, which are never invoked during normal operation by the companion mobile application, are fully processed by the hardware while the device is powered on.\nNetwork exposure is localized to the physical proximity required for BLE communication, typically within a range of approximately 10 meters, depending on environmental factors and radio output power. No authentication requirements or privilege requirements exist, as the firmware accepts commands from any unauthenticated central device that establishes a connection. The payload behavior results in the direct execution of hidden hardware-level routines, potentially overriding standard operational boundaries, altering stimulation delivery, or inducing erratic hardware states. The post-exploitation impact includes unauthorized control over a medical wellness device attached to the human body, creating direct safety and operational integrity risks."
}