Home

Description

A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionality of the component Bluetooth Low Energy Handler. Performing a manipulation results in cleartext transmission of sensitive information. The attack can only be performed from the local network. The attack's complexity is rated as high. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED Reserved 2026-02-18 | Published 2026-03-07 | Updated 2026-03-07 | Assigner VulDB




LOW: 2.3CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
LOW: 3.1CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R
LOW: 3.1CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R
1.8AV:A/AC:H/Au:N/C:P/I:N/A:N/E:ND/RL:ND/RC:UR

Problem types

Cleartext Transmission of Sensitive Information

Cryptographic Issues

Product status

V4
affected

Timeline

2026-03-07:Advisory disclosed
2026-03-07:VulDB entry created
2026-03-07:VulDB entry last update

Credits

drewbug (VulDB User) reporter

VulDB coordinator

References

vuldb.com/?id.349702 (VDB-349702 | Mendi Neurofeedback Headset Bluetooth Low Energy cleartext transmission) vdb-entry

vuldb.com/?ctiid.349702 (VDB-349702 | CTI Indicators (IOB, IOC, TTP)) signature permissions-required

vuldb.com/?submit.766457 (Submit #766457 | Mendi Innovation AB Mendi V4 Cleartext Transmission of Sensitive Information) third-party-advisory

ab3j.radio/mendi.pdf related

cve.org (CVE-2026-2671)

nvd.nist.gov (CVE-2026-2671)

Download JSON