CVE-2026-27510
Last modified
CVE-2026-27510 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integrity protection and validation of user-created programmes. The Android application stores programs in a local SQLite database (unitree_go2.db, table dog_programme) and transmits the programme_text content, including the pyCode field, to the robot. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integrity protection and validation of user-created programmes. The Android application stores programs in a local SQLite database (unitree_go2.db, table dog_programme) and transmits the programme_text content, including the pyCode field, to the robot. The robot's actuator_manager.py executes the supplied Python as root without integrity verification or content validation. An attacker with local access to the Android device can tamper with the stored programme record to inject arbitrary Python that executes when the user triggers the program via a controller keybinding, and the malicious binding persists across reboots. Additionally, a malicious program shared through the application's community marketplace can result in arbitrary code execution on any robot that imports and runs it.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Unitree | Go2 Firmware | >= 1.1.7, <= 1.1.11 |
References
- https://boschko.ca/unitree-go2-rce/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-27510?
How severe is CVE-2026-27510?
How do I fix CVE-2026-27510?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-27505SVXportal version 2.5 and prior contain a stored cross-site …6.1
- CVE-2026-27506SVXportal version 2.5 and prior contain a stored cross-site …5.4
- CVE-2026-27507Binardat 10G08-0800GSM network switch firmware version V300S…9.8
- CVE-2026-27508Smoothwall Express versions prior to 3.1 Update 13 contain a…6.1
- CVE-2026-27509Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.…8.5
- CVE-2026-2751Blind SQL Injection via unsanitized array keys in Service De…9.8
- CVE-2026-27511Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_mult…5.1
- CVE-2026-27512Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_mult…6.1
- CVE-2026-27513Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_mult…5.1
- CVE-2026-27514Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_mult…7.1
- CVE-2026-27515Binardat 10G08-0800GSM network switch firmware versions prio…9.3
- CVE-2026-27516Binardat 10G08-0800GSM network switch firmware version V300S…8.6
Are you affected by CVE-2026-27510?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
