← Back to home
ICSMA-25-364-01  ·  Published 2026-07-02  ·  View on CISA ICS-CERT ↗

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs (Update B)

CVSS 9.8 CRITICAL

Risk Summary

Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to take control over the product.

CVEs (1)

Remediations

  • WHILL has released Model C2 FW version HMI v3.00 and Model F FW version HMI v3.01 which includes a secure BLE design that has been recently authorized by the FDA.
  • For customers that previously disabled the BLE function as a mitigation to the vulnerability (refer to Update A dated March 24, 2026), customers can now re-enable the BLE function. To turn on the BLE function, contact WHILL Inc. prior to installing the new firmware.
  • For more information, see WHILL Inc.'s bulletin (https://whill.inc/us/urgent-medical-device-correction/).

Affected Vendors

WHILL Inc.

Affected Products (2)

WHILL Inc. · Model C2 Electric WheelChair <HMI_v3.00
WHILL Inc. · Model F Power Chair <HMI_v3.01

Affected Sectors

Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more