CVE-2026-18164
Received Received - Intake

Hard-Coded Credentials in Brain Stimulation Device

Vulnerability report for CVE-2026-18164, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: ICS-CERT

Description

An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an undocumented hard-coded credential shared across all device units. It allows authentication bypass, enabling attackers within Bluetooth range to manipulate brain stimulation parameters and device state without authorization.

Detection Guidance

Detection requires checking for unauthorized Bluetooth connections or unusual brain stimulation device activity. Monitor Bluetooth traffic for unexpected pairing attempts or commands. Use tools like Wireshark with Bluetooth capture filters or specialized medical device monitoring software.

Impact Analysis

An attacker could remotely alter brain stimulation settings, potentially causing unintended or harmful effects. Since the credential is shared, all devices are equally vulnerable, and physical proximity via Bluetooth is required for exploitation.

Compliance Impact

This vulnerability likely violates data integrity and security requirements under GDPR and HIPAA due to unauthorized access and potential manipulation of sensitive health-related data. Compliance may be compromised as unauthorized changes could lead to privacy breaches or unsafe device operation.

Mitigation Strategies

Immediately disable Bluetooth connectivity on affected devices if not required. Update device firmware to remove hard-coded credentials if a patch is available. Restrict physical access to devices to prevent unauthorized Bluetooth range attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18164. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart