Our takeCISA flags Flow Neuroscience FL-100 brain-stimulation devices: an attacker in Bluetooth range can alter stimulation parameters and override safety limits (CVSS 8.1). Proximity limits scale, not severity — if you use or prescribe one, check the advisory for mitigations.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA reports that Flow Neuroscience and Halo Neuroscience FL-100 tDCS devices have a Bluetooth vulnerability (CVSS 8.1) that lets nearby attackers change stimulation parameters and bypass safety limits. Update firmware immediately where these devices are in use and restrict Bluetooth pairing to trusted controllers only.
What this means for you — Lean IT orgs:If your clinic, wellness center or research team uses a Flow or Halo FL-100 brain stimulation device, update its firmware now. An attacker within Bluetooth range could change the stimulation settings and override safety limits.
What this means for you — MSP:Audit client environments for Flow Neuroscience or Halo Neuroscience FL-100 devices. Apply the vendor firmware update and advise limiting Bluetooth exposure or disabling it when the device is not actively paired.
What this means for you — Researcher:CISA advisory ICSMA-26-225-01 details a Bluetooth vulnerability (CVSS 8.1) in Flow Neuroscience and Halo Neuroscience FL-100 that allows nearby attackers to manipulate stimulation parameters and override safety limits. Affected versions listed in the CSAF.