CISA Issues Warning on WHILL Model C2 Wheelchair Takeover Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) has reported a critical security vulnerability in WHILL Model C2 electric wheelchairs and Model F power chairs. This flaw allows attackers to potentially control these devices via Bluetooth.
The Cybersecurity and Infrastructure Security Agency (CISA) has reported a critical security vulnerability in WHILL Model C2 electric wheelchairs and Model F power chairs. This flaw allows attackers to potentially control these devices via Bluetooth.
The vulnerability, identified as CVE-2025-14346, has been assigned a CVSS v3 score of 9.8, signifying its critical severity.
Discovered by security researchers from QED Secure Solutions, the flaw involves the lack of authentication mechanisms for critical functions in the WHILL mobility devices. This enables an attacker within Bluetooth range to take control of the wheelchair without user interaction or authorization.
CVE ID CVSS v3 Affected Products Vulnerability Type
CVE-2025-14346 9.8 WHILL Model C2 Electric Wheelchair, WHILL Model F Power Chair Missing Authentication for Critical Function
This flaw allows attackers to potentially control these devices via Bluetooth.
The affected products are extensively used in healthcare facilities and by individuals globally, posing a risk to vulnerable users. The vulnerability allows exploitation wirelessly from a standard Bluetooth range of approximately 30 feet. This could lead to unauthorized control of the wheelchair, causing disruptions such as sudden stops or redirection.
WHILL Inc., a manufacturer based in Japan, produces these wheelchairs intended for both indoor and outdoor use. The devices are equipped with advanced maneuverability controls but are now discovered to have significant security vulnerabilities.
The research team, including members from QED Secure Solutions, responsibly disclosed the vulnerability to CISA. The findings underline the security challenges in Internet of Medical Things (IoMT) devices, which often prioritize connectivity over robust security controls.
As of now, CISA has not confirmed if WHILL has developed patches or mitigations for this vulnerability. Users of the affected wheelchairs are advised to contact WHILL for security updates and to limit Bluetooth connectivity when not using companion applications. Healthcare facilities should review their deployments and implement additional security measures to prevent unauthorized Bluetooth access.
This advisory (ICSMA-25-364-01) was published on Fri, Dec 30, 2025, as part of CISA's efforts to secure industrial control systems and medical devices against emerging threats.
Based on reporting by GBHackers.
