A critical security vulnerability with a CVSS score of 9.8 has been identified in WHILL C2 power wheelchairs, potentially allowing attackers to remotely control the devices. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory warning that exploitation of this flaw could enable unauthorized manipulation of the wheelchairs, posing significant safety risks to users. The vulnerability highlights the growing concern over the security of connected medical and mobility devices.
CISA's advisory provides technical details and recommended mitigations for the WHILL C2 vulnerability, urging users and administrators to apply necessary updates and security measures. The agency also released an advisory for a separate product, AzeoTech DAQFactory, but the primary focus remains on the severe risk associated with the WHILL C2 flaw. Security experts emphasize the importance of promptly addressing such vulnerabilities in assistive technology to prevent potential exploitation and ensure user safety.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Multiple outlets reported that CVE-2025-14346 carries a CVSS score of 9.8 and could let attackers within Bluetooth range take control of WHILL mobility devices. Reports emphasized the safety risks, lack of known public exploitation, and CISA's recommendation to apply mitigations promptly.
CISA released an Industrial Control Systems advisory on security issues affecting WHILL C2 Wheelchairs, alongside a separate advisory for AzeoTech DAQFactory. The advisory provided technical details and mitigation recommendations for the WHILL flaw.
WHILL released mitigations on December 29, 2025, including firmware updates and enhanced security measures for device and app interactions affecting the vulnerable wheelchair models. Users were directed to contact the company for mitigation guidance.
Security researchers at QED Secure Solutions identified CVE-2025-14346 in WHILL Model C2 Electric Wheelchairs and Model F Power Chairs. The vulnerability stems from missing authentication for Bluetooth connections, allowing nearby attackers to pair without authorization and control movement and settings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehipaajournal.com
Open sourcesecurityonline.info
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.