CVE-2025-35027: Unitree Multiple Robotic Products Command Injection
Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpasupplicantrestart.sh shell script. All Unitree models use firmware derived from the same codebase (MIT Cheetah), and the two major forks are the G1 (humanoid) and Go2 (quadruped) branches.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-35027?
CVE-2025-35027 is categorized as a command injection vulnerability, which can potentially allow an attacker to execute arbitrary commands on affected robotic devices.
How do I fix CVE-2025-35027?
To mitigate CVE-2025-35027, update the firmware of your Unitree robotic products to the latest version provided by the manufacturer.
Which products are affected by CVE-2025-35027?
CVE-2025-35027 affects the Unitree Go2, G1, H1, and B2 robotic devices.
Can CVE-2025-35027 be exploited remotely?
Yes, the command injection vulnerability in CVE-2025-35027 can be exploited remotely through the BLE module by an attacker within Bluetooth range.
What are the potential impacts of CVE-2025-35027?
The exploitation of CVE-2025-35027 could lead to unauthorized control over the affected robots, resulting in compromised functionality and security.