Description
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt BLE packet data by using the df98b715d5c6ed2b25817b6f2554124a key and the 2841ae97419c2973296a0d4bdfe19a4f IV.
References (3)
Core 3
Core References
Various Sources
https://news.ycombinator.com/item?id=45381590
Various Sources
https://spectrum.ieee.org/unitree-robot-exploit
Scores
CVSS v3
4.7
EPSS
0.0017
EPSS Percentile
7.0%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-321
Status
published
Products (4)
Unitree/B2
< 2025-09-20
Unitree/G1
< 2025-09-20
Unitree/Go2
< 2025-09-20
Unitree/H1
< 2025-09-20
Published
Sep 26, 2025
Tracked Since
Feb 18, 2026