Description
WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user interaction.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
all
all
Credits
Billy Rios of the Exploit Development Team - QED Secure Solutions
Jesse Young of the Exploit Development Team - QED Secure Solutions
Brandon Rothel of the Exploit Development Team - QED Secure Solutions
Jonathan Butts of the Exploit Development Team - QED Secure Solutions
Henri Hein of the Exploit Development Team - QED Secure Solutions
Justin Boling of the Exploit Development Team - QED Secure Solutions
Nick Kulesza of the Exploit Development Team - QED Secure Solutions
Ken Natividad of the Exploit Development Team - QED Secure Solutions
Carl Schuett of the Exploit Development Team - QED Secure Solutions
References
www.cisa.gov/...vents/ics-medical-advisories/icsma-25-364-01