CVE-2026-1442: Unitree UPK files Hard-Coded Key

Published Feb 27, 2026
·
Updated

Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, and then trusted by a Unitree product, such as the Unitree Go2 and other models. This issue appears to affect all of Unitree’s current offerings as of February 26, 2026, and so should be considered a vulnerability in both the firmware generation and extraction processes. At the time of this release, there is no publicly-documented mechanism to subvert the update process and insert poisoned firmware packages without the equipment owner’s knowledge.

Affected Software

16 affected components
Unitree Go2
Unitree current offerings
All of the following
Unitree Go2 Edu Standard Firmware
Unitree Go2 Edu Standard
All of the following
Unitree Go2 Air Firmware
Unitree Go2 Air
All of the following
Unitree Go2 Pro Firmware
Unitree Go2 Pro
All of the following
Unitree Go2 X Firmware
Unitree Go2 X
All of the following
Unitree Go1 Air Firmware
Unitree Go1 Air
All of the following
Unitree Go1 Pro Firmware
Unitree Go1 Pro
All of the following
Unitree Go2 Edu Plus Firmware
Unitree Go2 Edu Plus

Event History

Feb 27, 2026
CVE Published
via MITRE·04:28 AM
Data Sourced
via MITRE·04:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:18 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-1442?

CVE-2026-1442 is considered a high severity vulnerability due to the potential for unauthorized modification of firmware updates.

2

How do I fix CVE-2026-1442?

To fix CVE-2026-1442, ensure that firmware updates are validated with secure key management practices and avoid using hard-coded keys.

3

What products are affected by CVE-2026-1442?

CVE-2026-1442 affects Unitree Go2 and other current offerings by Unitree.

4

What is the impact of CVE-2026-1442?

The impact of CVE-2026-1442 allows an attacker to alter firmware updates, potentially compromising device functionality and security.

5

Is there a public exploit available for CVE-2026-1442?

Yes, there are discussions and demonstrations of exploits related to CVE-2026-1442 available in public forums and repositories.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203