Security Flaw Found in Pulsetto Vagus Nerve Stimulator Device
A security flaw has been identified in the Pulsetto Vagus Nerve Stimulator, a wellness device used worldwide and manufactured by Lithuania-based Pulsetto. According to an advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the vulnerability involves 'hidden functionality' that could allow an attacker to disable the device's electrical safety mechanisms or alter its stimulation output settings without the user's knowledge.
The flaw, tracked as CVE-2026-18844, has been given a CVSS severity score of 8.1, indicating a high level of risk. It affects all versions of the device and falls under the Healthcare and Public Health critical infrastructure sector, meaning it could have real-world safety implications for users relying on the device for health-related purposes.
While this device is a consumer wellness product rather than typical business IT equipment, the incident is a useful reminder for small businesses that any internet-connected or smart device—from medical wearables to office equipment—can carry hidden vulnerabilities. Businesses that supply, recommend, or use connected health and wellness devices for staff wellbeing programs should stay alert to manufacturer security advisories and updates.