CVE 7.3 HIGH

Unitree Multiple Robotic Products Command Injection_CVE-2025-35027

7.3 / 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpa_supplicant_restart.sh shell script.

Basic Information

ID CVE-2025-35027
Source AHA
Published Sep 26, 2025 at 06:53
Modified Sep 26, 2025 at 07:25

Affected Product

Vendor Unitree
Product Go2
Affected Versions Unitree Go2 0
Unitre G1 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.