Vulnerability Description
The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unitree | Go1 Firmware | - |
| Unitree | Go1 | - |
Related Weaknesses (CWE)
References
- https://github.com/MAVProxyUser/YushuTechUnitreeGo1/blob/main/Unitree_report.pdfExploitThird Party Advisory
- https://github.com/unitreerobotics/unitree_ros/issues/120Issue TrackingThird Party Advisory
- https://takeonme.org/cves/cve-2025-2894/ExploitMitigationThird Party Advisory
- https://www.axios.com/2025/04/01/threat-spotlight-backdoor-in-chinese-robots-futPress/Media Coverage
- https://x.com/d0tslash/status/1730989109332607208Press/Media Coverage
FAQ
What is CVE-2025-2894?
CVE-2025-2894 is a vulnerability with a CVSS score of 6.6 (MEDIUM). The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession ...
How severe is CVE-2025-2894?
CVE-2025-2894 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-2894?
Check the references section above for vendor advisories and patch information. Affected products include: Unitree Go1 Firmware, Unitree Go1.