Critical Bluetooth flaw exposes Flow Neuroscience FL-100 device to local manipulation
Flow Neuroscience’s FL-100 brain-stimulation device contains a hard-coded credential that lets an attacker within Bluetooth range bypass authentication and override safety limits, CISA said on Aug 13 2026.
Source: CISA · August 14, 2026 at 12:02 AM · AI-assisted report
Single-source
KUALA LUMPUR, 14 AUGUST 2026 —
Listen to this article
DomainFork Audio · read aloud
Flow Neuroscience’s FL-100 brain-stimulation device contains a hard-coded credential that lets an attacker within Bluetooth range bypass authentication and override safety limits, CISA said on Aug 13 2026.
Market Impact
The vulnerability, tracked as CVE-2026-18164, affects every FL-100 unit—including the Halo and CV variants—sharing the same undocumented password. CISA rated the flaw high severity with a CVSS v3.1 base score of 8.1 and CVSS v4.0 base score of 7.2. Exploitation is limited to local proximity; remote attacks are not possible. The agency reported no known public incidents exploiting the flaw as of Aug 13 2026.
Flow Neuroscience advises users to install the latest firmware via the Flow app. CISA recommends minimising Bluetooth exposure, isolating device networks behind firewalls, and using up-to-date VPNs for remote access. The advisory classifies the device as critical infrastructure in healthcare, though it does not indicate any deployment in Malaysia.
Malaysian medical-device distributors and hospitals should verify whether inventory includes the FL-100 and apply the firmware update promptly, according to industry sources. No Malaysian company or regulator has issued guidance as of Aug 13 2026.