Description
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.
References (3)
Core 3
Core References
Various Sources
https://news.ycombinator.com/item?id=45381590
Various Sources
https://spectrum.ieee.org/unitree-robot-exploit
Scores
CVSS v3
5.0
EPSS
0.0002
EPSS Percentile
4.7%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (4)
Unitree/B2
< 2025-09-20
Unitree/G1
< 2025-09-20
Unitree/Go2
< 2025-09-20
Unitree/H1
< 2025-09-20
Published
Sep 26, 2025
Tracked Since
Feb 18, 2026