CVE-2025-35027

7.3

Unitree · Go2, G1, H1, B2 robotic devices

Unitree robotic devices contain a command injection vulnerability in their Bluetooth Low Energy Wi-Fi configuration interface, allowing attackers to execute commands as root.

Executive summary

A critical command injection vulnerability in Unitree robotic devices enables unauthorized root-level access via the Bluetooth Low Energy interface.

Vulnerability

The flaw exists in the Bluetooth Low Energy (BLE) Wi-Fi configuration service, where unsanitized input is passed to the wpa_supplicant_restart.sh shell script. An attacker within BLE range can inject malicious strings during the Wi-Fi configuration process to trigger arbitrary command execution with root privileges.

Business impact

Successful exploitation allows an attacker to gain full administrative control over the affected robotic units. This poses significant risks to operational security, including potential unauthorized surveillance, physical asset manipulation, and the ability to propagate the exploit to other vulnerable robots within proximity. Given the potential for total system compromise, this vulnerability represents a severe threat to environments deploying these autonomous platforms.

Remediation

Immediate Action: Update the firmware of all affected Unitree robotic units to the latest version provided by the manufacturer. If an update is not immediately available for a specific model, restrict access to the device's physical proximity to prevent BLE-based exploitation.

Proactive Monitoring: Review device access logs for unusual Wi-Fi configuration activity or unexpected service restarts. Monitor for abnormal network traffic patterns originating from the robots that may indicate post-exploitation command and control communication.

Compensating Controls: Disable the Bluetooth interface on the robotic units if it is not strictly required for current operations. Implement physical security controls to prevent unauthorized personnel from entering the radio frequency range necessary to establish a BLE connection with the devices.

Exploitation status

Public Exploit Available: Yes, a functional proof-of-concept exists as documented by researchers in the UniPwn repository.

Analyst recommendation

The severity of this vulnerability, combined with the availability of a functional proof-of-concept, necessitates immediate action. Organizations deploying Unitree robotics should prioritize firmware updates and implement strict physical and radio-frequency access controls. Failure to remediate could result in a complete loss of device integrity and control.

More Unitree CVEs

Sources

Originally found and disclosed by Andreas Makris, Kevin Finisterre, Konstantin Severov, with todb (coordinator), per the CVE Program record.