Goal Reached Thanks to every supporter β€” we hit 100%!

Goal: 1000 CNY Β· Raised: 1000 CNY

100.0%

CVE-2025-14346 β€” AI Deep Analysis Summary

CVSS 9.8 Β· Critical

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: WHILL Model C2 & F have an **Access Control Error**. Bluetooth lacks authentication. <br>⚠️ **Consequences**: Unauthorized control of the wheelchair. Critical safety risk for users.

Q2Root Cause? (CWE/Flaw)

πŸ›‘οΈ **Root Cause**: **CWE-306** (Missing Authentication for Critical Function). <br>❌ **Flaw**: Bluetooth connection does not verify identity before allowing control commands.

Q3Who is affected? (Versions/Components)

🏭 **Affected**: **WHILL** Company. <br>🦽 **Products**: Model C2 & Model F Electric Wheelchairs. <br>πŸ“… **Published**: Jan 5, 2026.

Q4What can hackers do? (Privileges/Data)

πŸ’€ **Attacker Actions**: Full remote control via Bluetooth. <br>πŸ“Š **Impact**: **High** Confidentiality, Integrity, and Availability (CVSS 3.1). Can manipulate device movement.

Q5Is exploitation threshold high? (Auth/Config)

πŸ”“ **Threshold**: **LOW**. <br>πŸ“Ά **Config**: No authentication required. No physical proximity constraints mentioned. Easy to exploit remotely via BLE.

Q6Is there a public Exp? (PoC/Wild Exploitation)

🚫 **Public Exp?**: **No**. `pocs` array is empty. <br>πŸ•΅οΈ **Status**: Theoretical vulnerability. No known wild exploitation yet.

Q7How to self-check? (Features/Scanning)

πŸ” **Self-Check**: Scan for WHILL BLE services. <br>πŸ§ͺ **Test**: Attempt connection without pairing/auth. If connected, vulnerable. <br>πŸ“± **Tool**: Bluetooth scanner apps.

Q8Is it fixed officially? (Patch/Mitigation)

πŸ› οΈ **Fix?**: **Unknown**. No patch info in data. <br>πŸ“’ **Source**: CISA Advisory ICSMA-25-364-01 issued. Check vendor for updates.

Q9What if no patch? (Workaround)

🚧 **Workaround**: **Disable Bluetooth** when not in use. <br>🚫 **Mitigation**: Keep device in a Faraday cage or powered off in public. Avoid pairing with unknown devices.

Q10Is it urgent? (Priority Suggestion)

πŸ”₯ **Urgency**: **CRITICAL**. <br>βš–οΈ **Priority**: High. Safety-critical medical device. Even without public exploit, the risk to human life is severe. Patch immediately if available.