CISA advisory ICSMA-26-225-01, released August 13, describes an undocumented credential hardcoded into the Flow Neuroscience FL-100 and shared by every unit shipped. The FL-100 is a transcranial direct current stimulation headset for major depressive disorder, worn at home. An attacker in Bluetooth range who knows the credential bypasses authentication and changes stimulation parameters and device state. The flaw is CVE-2026-18164, CWE-798, scored 8.1 on CVSS v3.1 and 7.2 on v4.
A hardcoded credential shared across a product line reduces the security of every unit to one secret. Because the same value lives in each device's firmware, recovering it once unlocks all of them, with no per-device isolation to contain the damage.
The consequence is unusual because the flaw touches control, not data. A stimulation headset regulates electrical current delivered to the wearer, so an intruder who alters its parameters interferes with a therapy in progress rather than reading records. Used at home, the device has no clinical staff nearby to notice trouble.
The timing stings. FDA cleared the FL-100 in late 2025 as the first at-home brain stimulation treatment for depression on the US market, and US availability began in the second quarter of 2026. Firmware released before July 2026 is affected, and NVD lists the Halo Neuroscience FL-100 under the same CVE. Flow Neuroscience ships the fix as a firmware update through the Flow companion app. A.C. Buglione reported the flaw to CISA.
The case shows how fast consumer neurotechnology is reaching patients over wireless links built for convenience. Pairing that assumes a cooperative user leaves little margin when the same interface governs a therapeutic output.
The vector is adjacent, so exposure ends at Bluetooth range, and confidentiality impact is none. Integrity and availability are both rated high, on a device that drives current into a patient's head. Per-unit pairing secrets are the minimum for hardware in this class, and they cost close to nothing at manufacturing time.