CVE-2025-14346
Unknown
Unknown - Not Provided
Bluetooth Authentication Bypass in WHILL Electric Wheelchairs Enables Remote Control
Publication date: 2026-01-05
Last updated on: 2026-01-05
Assigner: ICS-CERT
Description
Description
WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user interaction.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| whill | model_c2 | * |
| whill | model_f | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |