Home
HIGH: 8.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:HDefault status
unknown
Any version
affected
Default status
unknown
Any version
affected
Default status
unknown
Any version
affected
Default status
unknown
Any version
affected
Description
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within restart_wifi_ap and restart_wifi_sta).
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Any version
Any version
Any version
Any version
References
spectrum.ieee.org/unitree-robot-exploit
news.ycombinator.com/item?id=45381590