Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31217 | Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpa_supplicant_restart.sh shell script. All Unitree models use firmware derived from the same codebase (MIT Cheetah), and the two major forks are the G1 (humanoid) and Go2 (quadruped) branches. |
Mon, 12 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Unitree b2 Firmware
Unitree g1 Firmware Unitree go2 Firmware Unitree h1 Firmware |
|
| CPEs | cpe:2.3:h:unitree:b2:-:*:*:*:*:*:*:* cpe:2.3:h:unitree:g1:-:*:*:*:*:*:*:* cpe:2.3:h:unitree:go2:-:*:*:*:*:*:*:* cpe:2.3:h:unitree:h1:-:*:*:*:*:*:*:* cpe:2.3:o:unitree:b2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitree:g1_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitree:go2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitree:h1_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Unitree b2 Firmware
Unitree g1 Firmware Unitree go2 Firmware Unitree h1 Firmware |
Tue, 30 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Sep 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Unitree
Unitree b2 Unitree g1 Unitree go2 Unitree h1 |
|
| Vendors & Products |
Unitree
Unitree b2 Unitree g1 Unitree go2 Unitree h1 |
Fri, 26 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpa_supplicant_restart.sh shell script. | Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpa_supplicant_restart.sh shell script. All Unitree models use firmware derived from the same codebase (MIT Cheetah), and the two major forks are the G1 (humanoid) and Go2 (quadruped) branches. |
Fri, 26 Sep 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 26 Sep 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 26 Sep 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpa_supplicant_restart.sh shell script. | |
| Title | Unitree Multiple Robotic Products Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AHA
Published:
Updated: 2025-10-07T21:10:12.489Z
Reserved: 2025-04-15T20:41:31.524Z
Link: CVE-2025-35027
Updated: 2025-09-30T18:04:54.252Z
Status : Analyzed
Published: 2025-09-26T07:15:41.413
Modified: 2026-01-12T16:54:07.000
Link: CVE-2025-35027
No data.
OpenCVE Enrichment
Updated: 2025-09-29T09:31:31Z
EUVD