CVE-2025-2894
Last modified
CVE-2025-2894 is a medium-severity vulnerability rated 6.6/10 on the CVSS scale. The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.
Metrics
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Unitree | Go1 Firmware | All versions |
References
- https://github.com/MAVProxyUser/YushuTechUnitreeGo1/blob/main/Unitree_report.pdfExploit, Third Party Advisory
- https://github.com/unitreerobotics/unitree_ros/issues/120Issue Tracking, Third Party Advisory
- https://takeonme.org/cves/cve-2025-2894/Exploit, Mitigation, Third Party Advisory
- https://x.com/d0tslash/status/1730989109332607208Press/Media Coverage
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-2894?
How severe is CVE-2025-2894?
How do I fix CVE-2025-2894?
Are you affected by CVE-2025-2894?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
