CVE-2025-35027: Unitree Multiple Robotic Products Command Injection

Published Sep 26, 2025
·
Updated

Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpasupplicantrestart.sh shell script. All Unitree models use firmware derived from the same codebase (MIT Cheetah), and the two major forks are the G1 (humanoid) and Go2 (quadruped) branches.

Affected Software

12 affected components
Unitree Go2
Unitree G1
Unitree H1
Unitree B2
All of the following
Unitree G1 Firmware<=1.4.4
Unitree G1
All of the following
Unitree Go2 firmware<=1.1.8
Unitree Go2
All of the following
Unitree H1 Firmware<=1.4.4
Unitree H1
All of the following
Unitree B2 Firmware<=1.1.8
Unitree B2

Event History

Sep 26, 2025
CVE Published
via MITRE·06:53 AM
Data Sourced
via MITRE·06:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-35027?

CVE-2025-35027 is categorized as a command injection vulnerability, which can potentially allow an attacker to execute arbitrary commands on affected robotic devices.

2

How do I fix CVE-2025-35027?

To mitigate CVE-2025-35027, update the firmware of your Unitree robotic products to the latest version provided by the manufacturer.

3

Which products are affected by CVE-2025-35027?

CVE-2025-35027 affects the Unitree Go2, G1, H1, and B2 robotic devices.

4

Can CVE-2025-35027 be exploited remotely?

Yes, the command injection vulnerability in CVE-2025-35027 can be exploited remotely through the BLE module by an attacker within Bluetooth range.

5

What are the potential impacts of CVE-2025-35027?

The exploitation of CVE-2025-35027 could lead to unauthorized control over the affected robots, resulting in compromised functionality and security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203