Description

Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpa_supplicant_restart.sh shell script. All Unitree models use firmware derived from the same codebase (MIT Cheetah), and the two major forks are the G1 (humanoid) and Go2 (quadruped) branches.

INFO

Published Date :

2025-09-26T06:53:49.585Z

Last Modified :

2025-10-07T21:10:12.489Z

Source :

AHA
AFFECTED PRODUCTS

The following products are affected by CVE-2025-35027 vulnerability.

Vendors Products
Unitree
  • B2
  • B2 Firmware
  • G1
  • G1 Firmware
  • Go2
  • Go2 Firmware
  • H1
  • H1 Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact