CVE-2022-2675: Unitree Go 1 "Robot Dog" Unauthenticated Remote Power Down
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other versions may be affected, such as the A1.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Unitree Go 1 robotics platform vulnerability?
The vulnerability ID is CVE-2022-2675.
What is the severity of CVE-2022-2675?
The severity of CVE-2022-2675 is medium, with a severity value of 6.5.
How can an attacker exploit CVE-2022-2675?
An attacker can exploit CVE-2022-2675 by powering down the Unitree Go 1 robotics platform within normal RF range without authentication.
Which versions of the Unitree Go 1 robotics platform are affected by CVE-2022-2675?
Versions H0.1.7 and H0.1.9 of the Unitree Go 1 robotics platform (using firmware version 0.1.35) are affected by CVE-2022-2675.
How can I protect my Unitree Go 1 robotics platform?
To protect your Unitree Go 1 robotics platform, update the firmware to a version that is not vulnerable to CVE-2022-2675.