CISA advisory ICSMA-26-225-01, released August 13, describes an undocumented credential hardcoded into the Flow Neuroscience FL-100 and shared by every unit shipped. The FL-100 is a transcranial direct current stimulation headset for major depressive disorder, worn at home. An attacker in Bluetooth range who knows the credential bypasses authentication and changes stimulation parameters and device state. The flaw is CVE-2026-18164, CWE-798, scored 8.1 on CVSS v3.1 and 7.2 on v4.
The timing stings. FDA cleared the FL-100 in late 2025 as the first at-home brain stimulation treatment for depression on the US market, and US availability began in the second quarter of 2026. Firmware released before July 2026 is affected, and NVD lists the Halo Neuroscience FL-100 under the same CVE. Flow Neuroscience ships the fix as a firmware update through the Flow companion app. A.C. Buglione reported the flaw to CISA.
The vector is adjacent, so exposure ends at Bluetooth range, and confidentiality impact is none. Integrity and availability are both rated high, on a device that drives current into a patient's head. Per-unit pairing secrets are the minimum for hardware in this class, and they cost close to nothing at manufacturing time.