CVE-2025-2894
The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over…
Does this matter?
Lower severity and a low EPSS score (0.84%). Track it; it rarely justifies an emergency change on its own.
Description
The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.
- CVSS 3.1
- 6.6 MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.84% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-912
- Affected
- unitree/go1 firmware
- Source
- cve@takeonme.org
References
- https://github.com/MAVProxyUser/YushuTechUnitreeGo1/blob/main/Unitree_report.pdfExploit, Third Party Advisory
- https://github.com/unitreerobotics/unitree_ros/issues/120Issue Tracking, Third Party Advisory
- https://takeonme.org/cves/cve-2025-2894/Exploit, Mitigation, Third Party Advisory
- https://www.axios.com/2025/04/01/threat-spotlight-backdoor-in-chinese-robots-future-of-cybersecurityPress/Media Coverage
- https://x.com/d0tslash/status/1730989109332607208Press/Media Coverage
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.