CVE-2025-14346

CRITICAL

WHILL Model C2 Electric Wheelchair and Model F Power Chair - Unauthenticated Bluetooth Command Injection

Title source: llm
STIX 2.1

Description

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user interaction.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource government-resource
https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-364-01

Scores

CVSS v3 9.8
EPSS 0.0549
EPSS Percentile 91.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (2)
WHILL/Model C2 Electric Wheelchair all
WHILL/Model F Power Chair all
Published Jan 05, 2026
Tracked Since Feb 18, 2026