---
id: CVE-2026-85104
title: >-
  In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make
  unauthenticated changes to brain stimulation

  parameters.
summary: >-
  In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make
  unauthenticated changes to brain stimulation

  parameters.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-924
vendor: Sooma
product: Sooma tDCS Home Therapy
affected:
  - tdcs_home_therapy 2Gen
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:32:26.093'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85104'
references:
  - url: 'https://shop.soomamedical.com/pages/all-products'
    label: db4dfee8-a97e-4877-bfae-eba6d14a2166
tags:
  - nvd
  - cve.org
epss: 0.00159
epssPercentile: 0.04297
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T19:10:32.914600Z'
cvssSource: cna
ingestedAt: '2026-09-16T13:56:12.615Z'
---

## Overview

In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulation
parameters.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
