The Medtronic MyCareLink Patient Monitor drew ICSMA-25-205-01. Three findings: data on an unencrypted filesystem, a built-in account with an empty password, and an internal service that deserializes untrusted data. Top score around 6.8, all requiring physical access, and Medtronic reported no evidence of exploitation.

The physical-access requirement caps the severity. It does not excuse the findings. An empty-password account and cleartext storage are what a first-year secure-design review is supposed to catch. And home cardiac monitors sit on a nightstand for years, then get resold, returned and refurbished, so physical access is not exotic for a device that lives in a bedroom.

Medtronic auto-deployed updates. Credit to Ethan Morchy of Somerset Recon and Carl Mann. If you make home devices, assume the attacker will eventually hold the hardware and design the storage and accounts for that day.