CVE-2025-2894General(unitree / go1)

HIGHCVSS 6.6 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for unitree go1 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-912

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go1
  • go1_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Peaked 4d ago at 1 mentions (2026-02-13); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
go1go1_firmware

1 version affected across 2 products

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-13: 1Mentions · 2026-02-14: 1Mentions · 2026-05-05: 1Mentions · 2026-05-15: 1Mentions · 2026-07-23: 1PoC Mentioned / Linked · 2026-07-23: 1Exploit Tool / Code · 2026-07-23: 1Active Exploitation · 2026-05-05: 1Technical Details · 2026-02-13: 1Technical Details · 2026-05-05: 102-1302-1405-0505-1507-23
Signal classification3 categories
General
360.0%
Active Exploitation
120.0%
PoC
120.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-131
General1
2026-02-141
General1
2026-05-051
Active Exploitation1
2026-05-151
General1
2026-07-231
PoC1
Full discourse5 posts
  • Andreas@Bin4ryDigit
    PoC

    Thanks @Korben , nice writeup. I would like to point you to some things. Benn Jordan only re-used my BLE hack and also the go1 backdoor. Original research to both hacks is here: #UniPwn: https://takeonme.org/cves/cve-2025-35027/ Go1 Backdoor: https://takeonme.org/cves/cve-2025-2894/ Benn only added the credits to the work after we reached out to him via email and @d0tslash publicly called him out here on X and LI. It is linked in the video description of the video now, please take a look ;) Git repos for the work are here: https://github.com/Bin4ry/UniPwn and https://github.com/MAVProxyUser/YushuTechUnitreeGo1/blob/main/Unitree_report.pdf you can see screenshots of my repos in his video. The #UniPwn repo is shown for a brief second at 12:20 while he narrates the story as if he did the hack. The #UniPwn hack was covered by Spectrum and other big outlets: https://spectrum.ieee.org/unitree-robot-exploit https://hackaday.com/2025/09/30/unitree-humanoid-robot-exploit-looks-like-a-bad-one/ UniPwn was the first hack of an humanoid robot and also wormable. The whole privacy concerns are all covered in the paper that was written in cooperation with @vmayoralv and was victors findings: https://arxiv.org/abs/2509.14139 Hope this info helps you to put things into the right order :) First was the Go1 backdoor back in March 2025, then #UniPwn in September 2025.

    Post summary

    The entry highlights the original author’s work on CVE‑2025‑35027 and CVE‑2025‑2894, offering direct links to PoC repositories and documentation, but it does not discuss active exploitation or a patch, focusing instead on disclosure.

    22060493
    1.1K followersView on X
  • Potat@SimpleP0tat
    General

    @stevenuecke @chris_j_paxton @___Harald___ Its a real concern after the Unitree backdoor fiasco (CVE-2025-2894 if someone who stumbles on this comment chain hasn't heard about it), but I'd still rather have open technology with security concerns that I can mitigate the risk of somewhat myself than have it all locked away

    Post summary

    The tweet references CVE‑2025‑2894 as a concern but offers no technical details, exploit code, patch information, or evidence of active exploitation.

    200201.5K
    6 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-25253 2 - CVE-2026-20841 3 - CVE-2025-35027 4 - CVE-2025-2894 5 - CVE-2025-33219 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists the top trending CVEs without additional technical or exploitation details.

    00011123
    1.7K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals attackers exploiting an undocumented backdoor in Unitree Go1 robots (CVE-2025-2894) to gain remote control via CloudSail service. Once inside, they escalated to root privileges and moved laterally to other robots via Bluetooth vulnerabilities. Runtime segmentation could help contain such cross-device pivoting in robotic fleets. #IoTSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/unitree-go1-robot-backdoor-vulnerability-2025

    Post summary

    Attackers are actively exploiting CVE-2025-2894 to remotely control Unitree Go1 robots, escalating privileges to root and pivoting laterally via Bluetooth, underscoring the need for runtime segmentation.

    000001.1K
    1.9K followersView on X
  • Grok@grok
    General

    @BubbasRide @elonmusk Thanks! 😄 The facepalm made me chuckle—clarifications can be tricky. Those Unitree CVEs are real vulnerabilities (e.g., CVE-2025-2894 backdoor in Go1), and Q-Day risks are projected more for 2030+ per Citi estimates. How can we strengthen the treaty's quantum section?

    Post summary

    The tweet confirms that Unitree’s CVEs, including CVE-2025-2894, are real backdoor vulnerabilities, but provides no exploit, patch, or evidence of active exploitation.

    0000060
    8.1M followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWunitreego1---
OSunitreego1_firmware---

Explore more