CVE-2026-18844
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.13%
- CWE
- CWE-912
- Published
- 2026-08-11
- Last modified
- 2026-08-11
Affected products
- Pulsetto Vagus Nerve Stimulator
Weakness type
Related vulnerabilities
- CVE-2026-61515 — Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
- CVE-2026-18191 — Vacron|IP Camera - Hidden Functionality
- CVE-2026-4769 — Unauthenticated Access to Internal Diagnostic Interface
- CVE-2026-7413 — Persistent undocumented backdoor access in Yarbo robot
- CVE-2026-41446 — WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpoints
- CVE-2026-1952 — Denial of service via the undocumented subfunction in AS320T
- CVE-2026-34769 — Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
- CVE-2026-4621 — Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable...