CVE-2025-35027
7.3
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.1 / Impact: 5.2
Source: cve@takeonme.org (Secondary)
Description
Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpa_supplicant_restart.sh shell script. All Unitree models use firmware derived from the same codebase (MIT Cheetah), and the two major forks are the G1 (humanoid) and Go2 (quadruped) branches.
Affected (4)
Products: Unitree: G1 Firmware, Go2 Firmware, H1 Firmware, B2 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.4.4 |
| Running on/with | Platform Versions |
|---|---|
Unitree G1 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.1.8 |
| Running on/with | Platform Versions |
|---|---|
Unitree Go2 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.4.4 |
| Running on/with | Platform Versions |
|---|---|
Unitree H1 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.1.8 |
| Running on/with | Platform Versions |
|---|---|
Unitree B2 | All versions |
References (7)
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitTechnical Description
Timeline
No history available yet.