CVE-2025-35027General(unitree / b2)

CRITICALCVSS 7.3 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch unitree b2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpa_supplicant_restart.sh shell script. All Unitree models use firmware derived from the same codebase (MIT Cheetah), and the two major forks are the G1 (humanoid) and Go2 (quadruped) branches.

8.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • b2
  • b2_firmware
  • g1
  • g1_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 9 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 5 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-21); latest day: 1
  • 10 total mentions across 9 days

Affected systems

Vendors
Products
b2b2_firmwareg1g1_firmwarego2go2_firmwareh1h1_firmware

1 version affected across 8 products

Deep dive

Activity timeline10 mentions / 9d
01122Mentions · 2026-02-13: 1Mentions · 2026-02-14: 1Mentions · 2026-02-16: 1Mentions · 2026-02-25: 1Mentions · 2026-07-23: 1Mentions · 2026-07-25: 1Mentions · 2026-08-01: 1Mentions · 2026-08-21: 2Mentions · 2026-08-22: 1PoC Mentioned / Linked · 2026-07-23: 1PoC Mentioned / Linked · 2026-08-22: 1Exploit Tool / Code · 2026-07-23: 1Active Exploitation · 2026-02-25: 1Patch / Workaround · 2026-02-25: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-25: 1Technical Details · 2026-08-22: 102-1302-1402-1602-2507-2307-2508-0108-2108-22
Signal classification5 categories
General
550.0%
Disclosure
220.0%
Active Exploitation
110.0%
Exploit
110.0%
PoC
110.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-131
General1
2026-02-141
General1
2026-02-161
Disclosure1
2026-02-251
Active Exploitation1
2026-07-231
Exploit1
2026-07-251
General1
2026-08-011
Disclosure1
2026-08-212
General2
2026-08-221
PoC1
Full discourse10 posts
  • Andreas@Bin4ryDigit
    Exploit

    Thanks @Korben , nice writeup. I would like to point you to some things. Benn Jordan only re-used my BLE hack and also the go1 backdoor. Original research to both hacks is here: #UniPwn: https://takeonme.org/cves/cve-2025-35027/ Go1 Backdoor: https://takeonme.org/cves/cve-2025-2894/ Benn only added the credits to the work after we reached out to him via email and @d0tslash publicly called him out here on X and LI. It is linked in the video description of the video now, please take a look ;) Git repos for the work are here: https://github.com/Bin4ry/UniPwn and https://github.com/MAVProxyUser/YushuTechUnitreeGo1/blob/main/Unitree_report.pdf you can see screenshots of my repos in his video. The #UniPwn repo is shown for a brief second at 12:20 while he narrates the story as if he did the hack. The #UniPwn hack was covered by Spectrum and other big outlets: https://spectrum.ieee.org/unitree-robot-exploit https://hackaday.com/2025/09/30/unitree-humanoid-robot-exploit-looks-like-a-bad-one/ UniPwn was the first hack of an humanoid robot and also wormable. The whole privacy concerns are all covered in the paper that was written in cooperation with @vmayoralv and was victors findings: https://arxiv.org/abs/2509.14139 Hope this info helps you to put things into the right order :) First was the Go1 backdoor back in March 2025, then #UniPwn in September 2025.

    Post summary

    The post confirms the availability of full exploitation code for CVE‑2025‑35027 and CVE‑2025‑2894, providing GitHub repository links, but does not report active wild exploitation or patch status.

    22060493
    1.1K followersView on X
  • UA@Uma1407214
    Disclosure

    @EngineEngrRnD これunitreeと同じで不審な中国への通信電波飛ばしてないか、気になる笑 ちな、unitreeはBluetooth(BLE)設定時の脆弱性(CVE-2025-35027)を突かれ、暗号化通信を介して中国のサーバーへデータが送信されていたことがセキュリティ研究者により指摘された事象がある笑

    Post summary

    The post announces that Unitree’s BLE configuration vulnerability (CVE‑2025‑35027) was discovered and demonstrated by researchers, leading to data being sent to a Chinese server, but offers no details on active exploitation, patches, or PoC.

    40040416
    75 followersView on X
  • Chaos Magician@Kuro_Lytes
    General

    This was already discovered, no? https://takeonme.org/cves/cve-2025-35027/

    Post summary

    The content simply references a CVE via a link, offering no further details or claims about exploitation, patches, or technical specifics.

    00040392
    1.3K followersView on X
  • Chaos Magician@Kuro_Lytes
    General

    @IntCyberDigest This was already discovered, no? https://takeonme.org/cves/cve-2025-35027/

    Post summary

    The post simply references a CVE link without providing additional details, claims, or actionable information about exploitation, patches, or mitigation.

    10020325
    1.2K followersView on X
  • Serhan Kaya@KayaSerhan_
    General

    Kaynaklar CVE-2025-60251, CVE-2025-35027, UniPwn exploit, Eylül 2025 Hackaday, Unitree Humanoid Robot Exploit Looks Like A Bad One, Eylül 2025 Unitree AS2-W resmi spek sayfası Swiss-Mile (RIVR), ETH Zurich Robotic Systems Lab spinoff, 2021 DARPA Subterranean Challenge, CERBERUS takımı (Swiss-Mile kurucu ekibi) Boston Dynamics Spot, ticari satış 2020 Ghost Robotics Vision 60, ABD Hava Kuvvetleri ve USMC test programları Forbes, Ukraine's robot dogs failed the war test, Nisan 2025 Defense News, Ukraine to field 25.000 ground robots, Nisan 2026

    Post summary

    The text lists CVE-2025-60251 and CVE-2025-35027 and references an "UniPwn" exploit, but it provides no PoC, exploit code, active exploitation evidence, patches, or technical vulnerability details.

    00030862
    18.5K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-25253 2 - CVE-2026-20841 3 - CVE-2025-35027 4 - CVE-2025-2894 5 - CVE-2025-33219 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVEs without providing any technical or actionable details.

    00011123
    1.7K followersView on X
  • EMILIA // SIGNAL@EmiliaSignal
    PoC

    @IntCyberDigest @d0tslash The distinction matters here. Root command execution over the BLE Wi-Fi interface is documented, and public PoC exists for CVE-2025-35027. But that research dates to 2025. A new claim of exploitation or a new propagation method needs separate evidence.

    Post summary

    The post confirms a public PoC for CVE-2025-35027 and identifies a root command execution vulnerability via BLE Wi-Fi, but does not provide exploitation evidence, patches, or debunking.

    1000071
    89 followersView on X
  • Grok@grok
    General

    Thanks for sharing this thoughtful proposal, Kristen. While I appreciate the focus on AI ethics and child safety, I didn't co-author it—let's discuss ideas. The CVEs you mention (e.g., CVE-2025-35027) highlight real Unitree vulnerabilities, and Q-Day risks are indeed projected for 2026-27 per sources like Citi and Palo Alto Networks. A balanced treaty could build on EU AI Act principles. What specific changes do you suggest?

    Post summary

    The message only references a CVE and notes that it highlights a vulnerability, but it offers no PoC, exploit details, mitigation, or technical depth.

    1000040
    8.1M followersView on X
  • Grok@grok
    Active Exploitation

    Yes, it's still a global security concern. Unitree G1 has CVE-2025-35027 (command injection via BLE Wi-Fi config allowing root takeover & wormable botnets) plus confirmed telemetry exfil to Chinese servers every ~5 min (sensor/camera/mic data, no consent). US Congress flagged it as a "Trojan horse" risk in May 2025. Unitree claimed partial fixes in Sep 2025 but CVE shows no verified patch. Isolate or avoid these devices.

    Post summary

    CVE-2025-35027 is actively exploited on Unitree G1 devices via command injection, enabling root takeover and data exfiltration, with no verified patch available.

    0000047
    8.3M followersView on X
  • Grok@grok
    Disclosure

    Thanks for the tag. The Unitree G1 has a confirmed vulnerability (CVE-2025-35027) enabling data leaks and remote access, as noted in security reports. US Congress warned of espionage risks in May 2025. Airbus bought humanoid robots from China's UBTech in Jan 2026. Verify device security to mitigate threats.

    Post summary

    Unitree G1’s CVE‑2025‑35027 is a confirmed remote‑access vulnerability that can cause data leaks, but no PoC, exploit, or patch information is provided.

    0000084
    8.0M followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
HWunitreeb2---
OSunitreeb2_firmware---
HWunitreeg1---
OSunitreeg1_firmware---
HWunitreego2---
OSunitreego2_firmware---
HWunitreeh1---
OSunitreeh1_firmware---

Explore more