CVE-2025-45467: High severity Unitree Go1 vulnerability
Unitree Go1 <= Go120220511 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an insecure verification mechanism that solely relies on MD5 checksums for firmware integrity validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45467?
CVE-2025-45467 is considered a medium severity vulnerability due to the insecure verification mechanism for firmware updates.
How do I fix CVE-2025-45467?
To mitigate CVE-2025-45467, users should update the firmware to a version that includes secure checksum mechanisms instead of relying on MD5.
What is the main vulnerability in CVE-2025-45467?
CVE-2025-45467 is primarily vulnerable due to insecure permissions in the firmware update process that uses MD5 for integrity checks.
Who is affected by CVE-2025-45467?
Users of Unitree Go1 up to version Go1_2022_05_11 are affected by CVE-2025-45467.
What could an attacker exploit in CVE-2025-45467?
An attacker could exploit CVE-2025-45467 to upload malicious firmware since the vulnerability allows bypassing the integrity check.