Summary
Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to take control over the product.
The following versions of WHILL Model C2 Electric Wheelchairs and Model F Power Chairs are affected:
- Model C2 Electric WheelChair (CVE-2025-14346)
- Model F Power Chair (CVE-2025-14346)
| CVSS | Vendor | Equipment | Vulnerabilities |
|---|---|---|---|
| v3 9.8 | WHILL Inc. | WHILL Model C2 Electric Wheelchairs and Model F Power Chairs | Missing Authentication for Critical Function |
Background
- Critical Infrastructure Sectors: Healthcare and Public Health
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Japan
Vulnerabilities
CVE-2025-14346
WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user interaction.
Affected Products
WHILL Model C2 Electric Wheelchairs and Model F Power Chairs
Vendor:
WHILL Inc.
WHILL Inc.
Product Version:
WHILL Inc. Model C2 Electric WheelChair: vers:all/*, WHILL Inc. Model F Power Chair: vers:all/*
WHILL Inc. Model C2 Electric WheelChair: vers:all/*, WHILL Inc. Model F Power Chair: vers:all/*
Product Status:
known_affected
known_affected
Remediations
Mitigation
WHILL has deployed the following fixes on December 29th, 2025:
Mit
[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.
This article has been indexed from All CISA Advisories
Read the original article: