HIGH
Pulsetto
CVE published 2026-08-11
CVE-2026-18844
The Pulsetto Vagus Nerve Stimulator's firmware accepts undisclosed commands over its Bluetooth Low Energy (BLE) interface without authentication or encryption. These commands are not issued by the companion mobile application but are fully processed by the device when powered on. This vulnerability has a CVSS score of 7.2 and is classified as HIGH severity.