


Perceptive Security
SOC/SIEM Consultancy

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs
Published:
30 december 2025 om 12:00:00
Alert date:
30 december 2025 om 18:02:13
Source:
cisa.gov
Critical vulnerability in WHILL Model C2 Electric Wheelchairs and Model F Power Chairs allows attackers within Bluetooth range to take complete control without authentication. The vulnerability (CVE-2025-14346) enables unauthorized pairing, movement commands, speed restriction overrides, and configuration manipulation. CVSS score of 9.8 indicates critical severity. WHILL deployed fixes on December 29th, 2025 including device-side speed profile protection and unlock command restrictions. No known public exploitation reported to CISA at time of advisory.
Technical details
Mitigation steps:
Affected products:
WHILL Model C2 Electric Wheelchair
WHILL Model F Power Chair
Related links:
https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-364-01
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsma-25-364-01.json
https://www.cve.org/CVERecord?id=CVE-2025-14346
https://cwe.mitre.org/data/definitions/306.html
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
https://www.cisa.gov/notification
https://www.cisa.gov/privacy-policy
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
