Description
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within restart_wifi_ap and restart_wifi_sta).
References (3)
Core 3
Core References
Various Sources
https://news.ycombinator.com/item?id=45381590
Various Sources
https://spectrum.ieee.org/unitree-robot-exploit
Scores
CVSS v3
8.2
EPSS
0.0111
EPSS Percentile
61.7%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (4)
Unitree/B2
< 2025-09-20
Unitree/G1
< 2025-09-20
Unitree/Go2
< 2025-09-20
Unitree/H1
< 2025-09-20
Published
Sep 26, 2025
Tracked Since
Feb 18, 2026