CVE-2025-14346 - CVE House
Back to Database
Status published Critical CVE-2025-14346

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs...

Vulnerability Description

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user interaction.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-14346

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Billy Rios of the Exploit Development Team - QED Secure Solutions
  • Jesse Young of the Exploit Development Team - QED Secure Solutions
  • Brandon Rothel of the Exploit Development Team - QED Secure Solutions
  • Jonathan Butts of the Exploit Development Team - QED Secure Solutions
  • Henri Hein of the Exploit Development Team - QED Secure Solutions
  • Justin Boling of the Exploit Development Team - QED Secure Solutions
  • Nick Kulesza of the Exploit Development Team - QED Secure Solutions
  • Ken Natividad of the Exploit Development Team - QED Secure Solutions
  • Carl Schuett of the Exploit Development Team - QED Secure Solutions

Affected Vendor

Affected Software

Model C2 Electric Wheelchair, Model F Power Chair
Vulnerable Versions:
all

Timeline

Official Publish: January 5th, 2026
Last Modified: January 5th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)