CVE-2025-14346: Whill Model c2 Electric Wheelchair

Critical severity, CVSS 9.8. EPSS: 5.6% chance of exploitation in the next 30 days.

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user interaction.

Affected products

  • Whill Model c2 Electric Wheelchair: any version
  • Whill Model F Power Chair: any version

Published 2026-01-05. Last modified 2026-06-17.