PT-2026-23879 · Mendi · Mendi Neurofeedback Headset V4
Drewbug
+1
·
Published
2026-03-07
·
Updated
2026-03-07
·
CVE-2026-2671
CVSS v3.1
3.1
Low
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mendi Neurofeedback Headset version V4
Description
A vulnerability exists in the Bluetooth Low Energy Handler component of the Mendi Neurofeedback Headset V4, allowing for the cleartext transmission of sensitive information. The attack requires manipulation and can only be performed from the local network. Exploitation is considered difficult. The vendor was contacted regarding this issue but did not respond.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mendi Neurofeedback Headset V4