Security Flaw Found in Flow Neuroscience Brain Stimulation Device
CISA has issued an advisory for the Flow Neuroscience FL-100 (also sold as Halo Neuroscience FL-100), a brain stimulation device used in healthcare settings. The vulnerability, rated 8.1 out of 10 on the CVSS severity scale, stems from the use of hard-coded credentials — meaning a fixed, unchangeable password or key is built into the device's software.
Because of this flaw, an attacker within Bluetooth range of the device could potentially connect to it without proper authorisation and alter its stimulation parameters, overriding built-in safety limits. This poses a real risk to patient safety, particularly in healthcare and public health settings where the device is deployed. Flow Neuroscience is headquartered in Sweden, and the device is used worldwide.
While this device is medical rather than typical business IT equipment, the underlying lesson applies broadly: any connected device with fixed, unchangeable credentials is a serious security risk. Small businesses using Bluetooth-enabled medical, wellness, or IoT devices in their operations should check with vendors for firmware updates or advisories and restrict physical or wireless proximity to unauthorised users where possible.