CVE-2025-60251: Medium severity Unitree Go2 vulnerability
Published Sep 26, 2025
·Updated
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.
Affected Software
4 affected components
Unitree Go2<=2025-09-20
Unitree G1<=2025-09-20
Unitree H1<=2025-09-20
Unitree B2<=2025-09-20
Event History
Sep 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-60251?
CVE-2025-60251 has a high severity level due to its potential for unauthorized access.
2
How do I fix CVE-2025-60251?
To mitigate CVE-2025-60251, ensure that only authenticated handshake secrets are accepted and update your Unitree devices to the latest firmware.
3
Which devices are affected by CVE-2025-60251?
CVE-2025-60251 affects Unitree Go2, G1, H1, and B2 devices released until September 20, 2025.
4
What type of vulnerability is CVE-2025-60251?
CVE-2025-60251 is an authentication vulnerability that allows any handshake secret with the substring 'unitree'.
5
Is there a public exploit available for CVE-2025-60251?
Yes, there are reports of public exploits being demonstrated for CVE-2025-60251.