Description

The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.

INFO

Published Date :

2025-03-28T02:51:19.768Z

Last Modified :

2025-04-03T14:37:08.450Z

Source :

AHA
AFFECTED PRODUCTS

The following products are affected by CVE-2025-2894 vulnerability.

Vendors Products
Unitree
  • Go1
  • Go1 Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact