← Back

Unitree

unitree

10 CVEs • 30 products

Products (30)

Click to collapse
Toggle
Go1 Firmware
go1_firmware
Go2 Firmware
go2_firmware
A1 Firmware
a1_firmware
Go 1 Firmware
go_1_firmware
G1 Firmware
g1_firmware
H1 Firmware
h1_firmware
B2 Firmware
b2_firmware
Go2 X Firmware
go2_x_firmware
Go 1
go_1
A1
a1
Go1
go1
G1
g1
Go2
go2
H1
h1
B2
b2
Go2 Air
go2_air
Go2 Pro
go2_pro
Go2 X
go2_x
Go1 Air
go1_air
Go1 Pro
go1_pro
Go2 Edu Plus
go2_edu_plus
Go2 Edu
go2_edu

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Unitree
7Go1 Air Firmware
Go1 Pro FirmwareGo2 Air Firmware+4 more
Mar 11, 2026
Feb 27, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, a...Show more
Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, and then trusted by a Unitree product, such as the Unitree Go2 and other models. This issue appears to affect all of Unitree’s current offerings as of February 26, 2026, and so should be considered a vulnerability in both the firmware generation and extraction processes. At the time of this release, there is no publicly-documented mechanism to subvert the update process and insert poisoned firmware packages without the equipment owner’s knowledge.Show less
1Unitree
1Go2 Firmware
Mar 12, 2026
Feb 26, 2026
6.4 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integrity protection and validation of u...Show more
Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integrity protection and validation of user-created programmes. The Android application stores programs in a local SQLite database (unitree_go2.db, table dog_programme) and transmits the programme_text content, including the pyCode field, to the robot. The robot's actuator_manager.py executes the supplied Python as root without integrity verification or content validation. An attacker with local access to the Android device can tamper with the stored programme record to inject arbitrary Python that executes when the user triggers the program via a controller keybinding, and the malicious binding persists across reboots. Additionally, a malicious program shared through the application's community marketplace can result in arbitrary code execution on any robot that imports and runs it.Show less
1Unitree
2Go2 Edu Firmware
Go2 Firmware
May 26, 2026
Feb 26, 2026
8.5 HIGH· v4
8.0 HIGH· v3
N/A· v2
Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/programming_actuator/request handled by actuator_manager...Show more
Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/programming_actuator/request handled by actuator_manager.py. A network-adjacent, unauthenticated attacker can join DDS domain 0 and publish a crafted message (api_id=1002) containing arbitrary Python, which the robot writes to disk under /unitree/etc/programming/ and binds to a physical controller keybinding. When the keybinding is pressed, the code executes as root and the binding persists across reboots.Show less
1Unitree
4B2 Firmware
G1 FirmwareGo2 Firmware+1 more
Jan 12, 2026
Sep 26, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a...Show more
Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpa_supplicant_restart.sh shell script. All Unitree models use firmware derived from the same codebase (MIT Cheetah), and the two major forks are the G1 (humanoid) and Go2 (quadruped) branches.Show less
1Unitree
1Go1 Firmware
Jan 12, 2026
Jul 25, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.
1Unitree
1Go1 Firmware
Jan 12, 2026
Jul 25, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an insecure verification mechanism that solely relies on MD5 checksums for firmware...Show more
Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an insecure verification mechanism that solely relies on MD5 checksums for firmware integrity validation.Show less
1Unitree
1Go1 Firmware
Jan 12, 2026
Mar 28, 2025
N/A· v4
6.6 MEDIUM· v3
N/A· v2
The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API k...Show more
The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.Show less
1Unitree
1A1 Firmware
Nov 21, 2024
Nov 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Lack of authentication vulnerability. An unauthenticated local user is able to see through the cameras using the web server due to the lack of any form of authentication.
1Unitree
1A1 Firmware
Nov 21, 2024
Nov 22, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Authentication bypass vulnerability, the exploitation of which could allow a local attacker to perform a Man-in-the-Middle (MITM) attack on the robot's camera video stream. In addition, if a MITM attack is carried out, i...Show more
Authentication bypass vulnerability, the exploitation of which could allow a local attacker to perform a Man-in-the-Middle (MITM) attack on the robot's camera video stream. In addition, if a MITM attack is carried out, it is possible to consume the robot's resources, which could lead to a denial-of-service (DOS) condition.Show less
1Unitree
1Go 1 Firmware
Nov 21, 2024
Aug 5, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other...Show more
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other versions may be affected, such as the A1.Show less