CVE-2025-35027

Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpa_supplicant_restart.sh shell script. All Unitree models use firmware derived from the same codebase (MIT Cheetah), and the two major forks are the G1 (humanoid) and Go2 (quadruped) branches.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:unitree:g1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:unitree:g1:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:unitree:go2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:unitree:go2:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:unitree:h1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:unitree:h1:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:unitree:b2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:unitree:b2:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-09-26 07:15

Updated : 2026-01-12 16:54


NVD link : CVE-2025-35027

Mitre link : CVE-2025-35027

CVE.ORG link : CVE-2025-35027


JSON object : View

Products Affected

unitree

  • g1
  • go2_firmware
  • b2
  • h1
  • g1_firmware
  • go2
  • h1_firmware
  • b2_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')