CVE-2025-2894

MEDIUM

Go1 - RCE

Title source: llm
STIX 2.1

Description

The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.

Scores

CVSS v3 6.6
EPSS 0.0040
EPSS Percentile 60.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-912
Status published
Products (1)
unitree/go1_firmware
Published Mar 28, 2025
Tracked Since Feb 18, 2026