Hard‑coded Credential Vulnerability (CVE‑2026‑18164) in Flow Neuroscience FL‑100 Brain‑Stimulation Device
What It Is — CISA disclosed that all Flow Neuroscience FL‑100 (and Halo) brain‑stimulation units contain an undocumented hard‑coded credential. The credential bypasses authentication, enabling an attacker within Bluetooth range to manipulate stimulation parameters and override safety limits.
Exploitability — The credential is publicly known; exploitation requires only proximity, no additional code. CVSS v3.1 base score 8.1 (High). No public PoC is required, and active exploitation has not been reported, but the attack is feasible.
Affected Products — Flow Neuroscience FL‑100 and Halo Neuroscience FL‑100 devices shipped before July 2026.
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 – Logical Access: Hard‑coded credentials violate the principle of unique, managed identities for system access.
- Continuous Control Monitoring: Maintaining up‑to‑date firmware and logging Bluetooth connections provides audit‑ready evidence of control effectiveness.
- Healthcare Contractual Requirements: Many health‑tech buyers now require demonstrable SOC 2 compliance; remediation actions become part of the evidentiary trail auditors expect.
Recommended Actions
- Inventory all Flow Neuroscience devices and record current firmware versions.
- Patch Immediately – Deploy the latest firmware via the Flow app.
- Hardening – Disable unnecessary Bluetooth pairing, enforce device‑level authentication, and enable logging of all access attempts.
- Map to SOC 2 Controls – Align remediation steps with CC6.1 (Logical Access) and CC7.1 (System Operations); retain logs as audit evidence.
Source: CISA Advisory – ICSMA‑26‑225‑01