CVE-2025-2894

MEDIUM

Go1 - RCE

Title source: llm

Description

The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.

Scores

CVSS v3 6.6
EPSS 0.0040
EPSS Percentile 60.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-912
Status published

Affected Products (1)

unitree/go1_firmware

Timeline

Published Mar 28, 2025
Tracked Since Feb 18, 2026