CVE-2025-60250: Medium severity Unitree Go2 vulnerability
Published Sep 26, 2025
·Updated
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt BLE packet data by using the df98b715d5c6ed2b25817b6f2554124a key and the 2841ae97419c2973296a0d4bdfe19a4f IV.
Affected Software
4 affected components
Unitree Go2<=2025-09-20
Unitree G1<=2025-09-20
Unitree H1<=2025-09-20
Unitree B2<=2025-09-20
Event History
Sep 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What are the affected devices by CVE-2025-60250?
The affected devices include Unitree Go2, G1, H1, and B2 models up to version 2025-09-20.
2
What is the vulnerability CVE-2025-60250 about?
CVE-2025-60250 allows the decryption of BLE packet data using a specific key and IV.
3
What is the potential impact of CVE-2025-60250?
The vulnerability could lead to unauthorized access to sensitive data transmitted via Bluetooth.
4
How is CVE-2025-60250 exploited?
Attackers can exploit CVE-2025-60250 by intercepting BLE packets and decrypting them using the known key and IV.
5
What should users do to protect themselves from CVE-2025-60250?
Users should update their Unitree devices to a version released after September 20, 2025 to mitigate the risk.