Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
WHILL has deployed the following fixes on December 29th, 2025: Device-Side Speed Profile Protection: * Implemented a safeguard in the wheelchair firmware to prevent unauthorized modification of speed profiles from the mobile application. Unlock Command Restriction During Motion: * Block unlock commands issued from either the mobile app or the smart key while the wheelchair is in motion. Application JSON File Obfuscation: * Obfuscate the configuration files used by the mobile application by converting JSON files into a binary format on both Android and iOS platforms.
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user interaction. | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-01-05T21:20:30.650Z
Reserved: 2025-12-09T14:54:28.374Z
Link: CVE-2025-14346
Updated: 2026-01-05T21:20:27.327Z
Status : Received
Published: 2026-01-05T16:15:41.843
Modified: 2026-01-05T16:15:41.843
Link: CVE-2025-14346
No data.
OpenCVE Enrichment
No data.