Pulsetto Vagus Nerve Stimulator

Plan PatchCVSS 8.1ICS-CERT ICSMA-26-223-02Aug 11, 2026
Energy
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

The Pulsetto Vagus Nerve Stimulator contains a vulnerability that allows attackers to use hidden commands to disable electrical safety mechanisms or modify stimulation output settings. All versions are affected. The vendor has not engaged with CISA and has not released a patch.

What this means
What could happen
An attacker could disable safety mechanisms on the nerve stimulator or alter its output settings, potentially causing patient harm or device malfunction during operation.
Who's at risk
Healthcare facilities, clinics, and home users who operate Pulsetto Vagus Nerve Stimulator devices are affected. This includes hospitals with pain management programs, neurology departments, and patients using the device for treatment.
How it could be exploited
An attacker with access to the device's communication interface could send hidden commands to bypass safety controls or change stimulation parameters without authorization or detection by the operator.
Prerequisites
  • Access to the device's communication interface (likely Bluetooth or USB)
  • Knowledge of hidden command syntax
no patch availableaffects safety systemsallows disabling safety mechanisms
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (1)
ProductAffected VersionsFix Status
Pulsetto Vagus Nerve StimulatorAll versionsNo fix yet
Remediation & Mitigation
0/4
Do now
0/3
WORKAROUNDContact Pulsetto directly at info@pulsetto.tech to request a security patch and request guidance on interim safety measures
HARDENINGRestrict physical and wireless access to the stimulator devices; disable Bluetooth or other wireless connectivity when not actively in use
WORKAROUNDImplement close monitoring of device operations during patient treatment; document baseline output settings and verify them before each session
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HARDENINGIf available, isolate stimulator communication from general network infrastructure; do not connect devices to shared clinical networks
API: /api/v1/advisories/4c7fabea-3c11-4e2f-8a8b-acc9f4719179

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.