Flow Neuroscience FL-100

Plan PatchCVSS 8.1ICS-CERT ICSMA-26-225-01Aug 13, 2026
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

The FL-100 brain stimulation device contains a Bluetooth authentication vulnerability (CWE-798: hardcoded credentials) that allows an attacker within wireless range to send commands that manipulate stimulation parameters and override safety limits without user knowledge or authorization. Affected versions: Flow Neuroscience FL-100 and Halo Neuroscience FL-100 firmware prior to July 2026.

What this means
What could happen
An attacker within Bluetooth range could manipulate brain stimulation settings and bypass safety limits on the FL-100 device, potentially causing harmful electrical stimulation or device malfunction.
Who's at risk
Healthcare providers and patients using Flow Neuroscience FL-100 or Halo Neuroscience FL-100 brain stimulation devices for therapeutic treatment. This affects any facility or home environment where the device is in active use.
How it could be exploited
An attacker with Bluetooth proximity to the FL-100 device could send unauthorized commands to modify stimulation parameters without authentication, overriding built-in safety constraints that normally protect the patient.
Prerequisites
  • Bluetooth wireless range to the FL-100 device (typically 10-30 meters depending on environment)
  • No authentication credentials required
remotely exploitableno authentication requiredlow complexityaffects medical safety systemsdefault/no credentials protection
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (2)
2 pending
ProductAffected VersionsFix Status
Flow Neuroscience FL-100<July 2026No fix yet
Halo Neuroscience FL-100<July 2026No fix yet
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate FL-100 firmware to July 2026 release or later using the Flow app
API: /api/v1/advisories/5377d83c-1bcc-4af5-bba1-ab55697b6d5f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.