CVE-2025-60017: OS Command Injection
Published Sep 26, 2025
·Updated
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapdrestart.sh wifissid or wifipass parameter (within restartwifiap and restartwifista).
Affected Software
4 affected components
Unitree Go2<=2025-09-20
Unitree G1<=2025-09-20
Unitree H1<=2025-09-20
Unitree B2<=2025-09-20
Event History
Sep 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-60017?
CVE-2025-60017 is considered a high severity vulnerability due to the potential for root OS command injection.
2
How do I fix CVE-2025-60017?
To fix CVE-2025-60017, update your Unitree Go2, G1, H1, or B2 devices to a version released after September 20, 2025.
3
What type of devices are affected by CVE-2025-60017?
CVE-2025-60017 affects Unitree Go2, G1, H1, and B2 devices released until September 20, 2025.
4
What is the impact of CVE-2025-60017?
The impact of CVE-2025-60017 includes the possibility for attackers to execute arbitrary commands on the affected devices.
5
What are the affected parameters in CVE-2025-60017?
CVE-2025-60017 specifically affects the wifi_ssid and wifi_pass parameters within the hostapd_restart.sh script.