What is CVE-2026-18164?
This vulnerability exposes an undocumented hard-coded credential that is identical across all device units. An attacker within Bluetooth range can bypass authentication and arbitrarily manipulate brain stimulation parameters and state. The device firmware must be updated immediately, and the manufacturer must implement a secure authentication mechanism.
Azərbaycanca: Bu zəiflik cihazda sənədləşdirilməmiş, bütün qurğular üçün eyni olan sərt kodlu etimadnaməni aşkar edir. Bluetooth məsafəsində olan təcavüzkar autentifikasiyanı keçərək beyin stimulyasiya parametrlərini özbaşına manipulyasiya edə bilər. Cihazın proqram təminatı dərhal yenilənməli və istehsalçı tərəfindən təhlükəsiz autentifikasiya mexanizmi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Where does an attacker need to be located to exploit CVE-2026-18164?
Within Bluetooth range.
What can an attacker manipulate if CVE-2026-18164 is successfully exploited?
Brain stimulation parameters.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.