Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Researchers Expose WHILL Wheelchair Safety Risks via Remote Hacking

Posted on January 8, 2026January 8, 2026 By CWS

Safety researchers have demonstrated a essential vulnerability in high-tech electrical wheelchairs that enables for unauthorized distant management, highlighting new security dangers for related mobility gadgets.

On December 30, the US cybersecurity company CISA revealed an advisory to tell the general public a couple of critical vulnerability found by researchers in electrical wheelchairs made by WHILL, a Japan-based firm whose private electrical mobility gadgets are offered all over the world.

In line with CISA’s advisory, WHILL Mannequin C2 and Mannequin F electrical wheelchairs are affected by a lacking authentication vulnerability. The difficulty is tracked as CVE-2025-14346 and it has been assigned a essential severity score. 

CISA mentioned the WHILL wheelchairs didn’t implement authentication for Bluetooth connections, permitting an attacker who’s in Bluetooth vary of the focused gadget to pair with it. The attacker may then management the wheelchair’s actions, override pace restrictions, and manipulate configuration profiles, all with out requiring credentials or person interplay. 

The flaw was found by a staff from QED Safe Options, a research-driven cybersecurity agency that helps personal and authorities organizations safe operational know-how (OT) and different essential programs. 

QED researchers have been demonstrating assaults with a probably extreme influence for a few years. Almost a decade in the past, on the Black Hat convention, they confirmed how hackers may trigger bodily harm to autos and injure their occupants by remotely hacking a automobile wash.Commercial. Scroll to proceed studying.

QED co-founder Billy Rios informed SecurityWeek that the vulnerability in WHILL wheelchairs was found throughout an annual hackathon organized by the corporate in 2025. 

“We normally decide a know-how, buy it, journey to a central location, after which spend per week or two hacking it,” Rios, who’s a good safety researcher, defined. 

Throughout their experiments, QED researchers efficiently gained bodily management of the wheelchair, maneuvering the gadget utilizing a keyboard and a recreation controller. By disabling built-in security options, the researchers had been capable of function the wheelchair at speeds exceeding its supposed remote-control parameters.

To show a high-impact theoretical situation, the staff developed an exploit designed to routinely compromise any WHILL wheelchair inside proximity. SecurityWeek reviewed a video demonstration of this exploit, which confirmed a wheelchair being remotely pushed off a flight of stairs at excessive pace.

Whereas an attacker should initially be inside Bluetooth vary to execute the exploit, Rios famous that it’s theoretically attainable to keep up management even after the gadget strikes out of the unique vary. “We didn’t show this, however it’s attainable,” Rios mentioned.

WHILL additionally has an autonomous wheelchair mannequin, however Rios mentioned they’ve but to check it. 

In line with CISA’s advisory, WHILL issued a patch and deployed mitigations for a number of safety points in late December 2025. Nevertheless, Rios acknowledged that his staff was not supplied with the replace, leaving them unable to confirm whether or not it successfully prevents the documented assaults. It’s unclear whether or not the patch is routinely deployed to gadgets or if customers need to manually set up it. 

Rios identified that whereas the analysis was carried out “for enjoyable”, the vulnerability raises critical questions in regards to the safety of WHILL merchandise.

The seller has obtained FDA clearance for its merchandise, however the authorities company is probably going not conscious that WHILL wheelchairs lacked important protections, reminiscent of robust authentication and encryption, and firmware code signing, the researcher mentioned.

“That is particularly troubling, on condition that we demonstrated clear patient-safety dangers related to their wheelchairs,” Rios mentioned.

WHILL has not responded to SecurityWeek’s request for remark. 

Associated: Free Wi-Fi Leaves Buses Weak to Distant Hacking

Associated: Distant CarPlay Hack Places Drivers at Threat of Distraction and Surveillance

Security Week News Tags:Expose, Hacking, Remote, Researchers, Risks, Safety, Wheelchair, WHILL

Post navigation

Previous Post: CISA Adds HP Enterprise OneView Code Injection Vulnerability to KEV Following Active Exploitation
Next Post: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More Stories

Related Posts

New AI Jailbreak Bypasses Guardrails With Ease Security Week News
US Offering $10 Million Reward for RedLine Malware Developer Security Week News
Descope Raises $35 Million in Seed Round Extension Security Week News
Extortion Group Leaks Millions of Records From Salesforce Hacks Security Week News
Red Teaming AI: The Build Vs Buy Debate Security Week News
377,000 Impacted by Data Breach at Texas Gas Station Firm Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
  • xRAT Malware Attacking Windows Users Disguised as Adult Game
  • Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials
  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k
  • Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
  • xRAT Malware Attacking Windows Users Disguised as Adult Game
  • Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials
  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k
  • Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark