Description
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
Any version
Any version
Any version
Any version
References
spectrum.ieee.org/unitree-robot-exploit
news.ycombinator.com/item?id=45381590