CVE-2025-14346

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user interaction.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Las sillas de ruedas eléctricas WHILL Modelo C2 y las sillas de ruedas motorizadas Modelo F no aplican autenticación para las conexiones Bluetooth. Un atacante dentro del alcance puede emparejarse con el dispositivo y emitir comandos de movimiento, anular las restricciones de velocidad y manipular perfiles de configuración sin credenciales ni interacción del usuario.

05 Jan 2026, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-05 16:15

Updated : 2026-06-17 08:35


NVD link : CVE-2025-14346

Mitre link : CVE-2025-14346

CVE.ORG link : CVE-2025-14346


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function