ICSMA-25-364-01
·
Published 2026-07-02
·
View on CISA ICS-CERT ↗
WHILL Model C2 Electric Wheelchairs and Model F Power Chairs (Update B)
CVSS 9.8
CRITICAL
Risk Summary
Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to take control over the product.
CVEs (1)
Remediations
- WHILL has released Model C2 FW version HMI v3.00 and Model F FW version HMI v3.01 which includes a secure BLE design that has been recently authorized by the FDA.
- For customers that previously disabled the BLE function as a mitigation to the vulnerability (refer to Update A dated March 24, 2026), customers can now re-enable the BLE function. To turn on the BLE function, contact WHILL Inc. prior to installing the new firmware.
- For more information, see WHILL Inc.'s bulletin (https://whill.inc/us/urgent-medical-device-correction/).
Affected Vendors
WHILL Inc.
Affected Products (2)
WHILL Inc.
·
Model C2 Electric WheelChair
<HMI_v3.00
WHILL Inc.
·
Model F Power Chair
<HMI_v3.01
Affected Sectors
Healthcare and Public Health
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more