Executive Summary

A critical security vulnerability, identified as CVE-2025-14346, affects all versions of WHILL Model C2 Electric Wheelchairs and Model F Power Chairs. The flaw, rated with a CVSS score of 9.8 (CRITICAL), stems from a lack of authentication for Bluetooth connections. This allows any attacker within Bluetooth range to pair with and assume control of the devices without requiring credentials or user interaction. Successful exploitation enables an attacker to issue movement commands, override speed restrictions, and manipulate the wheelchair’s configuration profiles.

In response, the vendor, WHILL Inc., deployed several mitigations on December 29, 2025, including firmware safeguards against unauthorised speed profile modification, restrictions on unlock commands while in motion, and obfuscation of mobile application configuration files. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued general recommendations for network security and defensive measures. As of the advisory’s release on December 30, 2025, there are no known public reports of this vulnerability being actively exploited.

Vulnerability Analysis

Vulnerability Details (CVE-2025-14346)

The core vulnerability is categorised as CWE-306: Missing Authentication for Critical Function. The affected WHILL electric wheelchairs do not enforce any authentication mechanism for their Bluetooth connections. This design flaw creates a critical attack vector.

Affected Products

The vulnerability impacts all versions of the following products from WHILL Inc., a company headquartered in Japan. These devices are deployed worldwide within the Healthcare and Public Health sectors.

Vendor Product Versions Status
WHILL Inc. Model C2 Electric WheelChair All Known Affected
WHILL Inc. Model F Power Chair All Known Affected

Severity Assessment

The vulnerability has been assigned a critical severity rating based on the Common Vulnerability Scoring System (CVSS).

This vector indicates an easily exploitable vulnerability over the network (Bluetooth), requiring no privileges or user interaction, with a high impact on confidentiality, integrity, and availability.

Mitigation and Response

Vendor Mitigations

WHILL Inc. deployed the following mitigations on December 29, 2025, to address the vulnerability:

CISA Recommended Practices

CISA recommends that users and organisations take general defensive measures to minimise the risk of exploitation for all industrial control systems (ICS). While not specific to this device, these practices enhance overall security posture:

Advisory Context

Secret Link