Unitree records
10 published records for vendor unitree.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-306 Missing Authentication for Critical Function2
- CWE-285 Improper Authorization1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-321 Use of Hard-coded Cryptographic Key1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2025-45466Proof of concept | Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.unitree · go1 firmware · CWE-798 | High8.8 | — | 0.6% | Jul 25, 2025 |
34Monitor | CVE-2026-27509No exploit | Unitree Go2 Missing DDS Authentication Enables Adjacent RCEunitree · go2 firmware · CWE-306 | High8.5 | — | 0.4% | Feb 26, 2026 |
31Monitor | CVE-2026-1442No exploit | Unitree UPK files Hard-Coded Keyunitree · go2 edu plus firmware · CWE-321 | High7.8 | — | 0.2% | Feb 27, 2026 |
30Monitor | CVE-2025-35027No exploit | Unitree Multiple Robotic Products Command Injectionunitree · g1 firmware · CWE-78 | High7.3 | — | 2.7% | Sep 26, 2025 |
30Monitor | CVE-2023-3104No exploit | Missing Authentication for Critical Function in Unitree Robotics A1unitree · a1 firmware · CWE-306 | High7.5 | — | 0.5% | Nov 22, 2023 |
28Monitor | CVE-2025-45467Proof of concept | Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an unitree · go1 firmware · CWE-276 | High7.1 | — | 0.3% | Jul 25, 2025 |
26Monitor | CVE-2025-2894No exploit | Unitree Go1 Robot Dog Backdoor Control Channelunitree · go1 firmware · CWE-912 | Medium6.6 | — | 0.9% | Mar 27, 2025 |
26Monitor | CVE-2022-2675No exploit | Unitree Go 1 "Robot Dog" Unauthenticated Remote Power Downunitree · go 1 firmware · CWE-285 | Medium6.5 | — | 0.5% | Aug 5, 2022 |
25Monitor | CVE-2026-27510No exploit | Unitree Go2 Mobile Program Tampering Enables Root RCEunitree · go2 firmware · CWE-345 | Medium6.4 | — | 0.4% | Feb 26, 2026 |
23Monitor | CVE-2023-3103No exploit | Authentication Bypass by Spoofing in Unitree Robotics A1unitree · a1 firmware · CWE-290 | Medium5.9 | — | 0.6% | Nov 22, 2023 |
- CVE-2025-4546635Monitor
Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.
HighCVSS 8.8Proof of conceptEPSS 1%unitree · go1 firmwareJul 25, 2025
- CVE-2026-2750934Monitor
Unitree Go2 Missing DDS Authentication Enables Adjacent RCE
HighCVSS 8.5No exploitEPSS 0%unitree · go2 firmwareFeb 26, 2026
- CVE-2026-144231Monitor
Unitree UPK files Hard-Coded Key
HighCVSS 7.8No exploitEPSS 0%unitree · go2 edu plus firmwareFeb 27, 2026
- CVE-2025-3502730Monitor
Unitree Multiple Robotic Products Command Injection
HighCVSS 7.3No exploitEPSS 3%unitree · g1 firmwareSep 26, 2025
- CVE-2023-310430Monitor
Missing Authentication for Critical Function in Unitree Robotics A1
HighCVSS 7.5No exploitEPSS 1%unitree · a1 firmwareNov 22, 2023
- CVE-2025-4546728Monitor
Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an
HighCVSS 7.1Proof of conceptEPSS 0%unitree · go1 firmwareJul 25, 2025
- CVE-2025-289426Monitor
Unitree Go1 Robot Dog Backdoor Control Channel
MediumCVSS 6.6No exploitEPSS 1%unitree · go1 firmwareMar 27, 2025
- CVE-2022-267526Monitor
Unitree Go 1 "Robot Dog" Unauthenticated Remote Power Down
MediumCVSS 6.5No exploitEPSS 1%unitree · go 1 firmwareAug 5, 2022
- CVE-2026-2751025Monitor
Unitree Go2 Mobile Program Tampering Enables Root RCE
MediumCVSS 6.4No exploitEPSS 0%unitree · go2 firmwareFeb 26, 2026
- CVE-2023-310323Monitor
Authentication Bypass by Spoofing in Unitree Robotics A1
MediumCVSS 5.9No exploitEPSS 1%unitree · a1 firmwareNov 22, 2023