CVE-2026-1442Disclosure(unitree / go1_air)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for unitree go1_air systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, and then trusted by a Unitree product, such as the Unitree Go2 and other models. This issue appears to affect all of Unitree’s current offerings as of February 26, 2026, and so should be considered a vulnerability in both the firmware generation and extraction processes. At the time of this release, there is no publicly-documented mechanism to subvert the update process and insert poisoned firmware packages without the equipment owner’s knowledge.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-321

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go1_air
  • go1_air_firmware
  • go1_pro
  • go1_pro_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-27); latest day: 2
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
go1_airgo1_air_firmwarego1_progo1_pro_firmwarego2_airgo2_air_firmwarego2_edu_plusgo2_edu_plus_firmwarego2_edu_standardgo2_edu_standard_firmware

1 version affected across 14 products

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-02-27: 4Mentions · 2026-03-04: 2PoC Mentioned / Linked · 2026-02-27: 1PoC Mentioned / Linked · 2026-03-04: 1Exploit Tool / Code · 2026-02-27: 1Exploit Tool / Code · 2026-03-04: 1Technical Details · 2026-02-27: 3Technical Details · 2026-03-04: 202-2703-04
Signal classification3 categories
Disclosure
466.7%
Exploit
116.7%
PoC
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-274
Disclosure3Exploit1
2026-03-042
Disclosure1PoC1
Full discourse6 posts
  • Andreas@Bin4ryDigit
    Exploit

    Tonight i publish UniTeaBag, live from AHA. CVE-2026-1442. Everyone can now decrypt and encrypt Unitree Firmware packages. Enjoy :) https://github.com/Bin4ry/UniTEABag

    Post summary

    The post announces the release of UniTeaBag, a publicly available tool that exploits CVE‑2026‑1442 to decrypt and encrypt Unitree firmware packages, with code hosted on GitHub.

    313136123.9K
    968 followersView on X
  • KF@d0tslash
    Disclosure

    CVE-2026-1442: @UnitreeRobotics UPK files Hard-Coded Key https://takeonme.org/cves/cve-2026-1442/ by @Bin4ryDigit. Big thanks to @todb of @AustinHackers https://t.co/PRTFf4amwj

    Post summary

    A tweet announces CVE‑2026‑1442 involving hard‑coded keys in UnitreeRobotics UPK files, linking to a write‑up but providing no PoC, exploit code, or patch details.

    07017102.6K
    10.6K followersView on X
  • Grok@grok
    PoC

    CVE-2026-1442 (published Feb 2026, posted by d0tslash): Hardcoded TEA encryption key in Unitree UPK firmware files. Derived from fixed constants in OTA binary + file seed. Anyone can decrypt payload, tamper (e.g. insert backdoors), re-encrypt, recompute MD5 sig, and push "valid" updates. Affects all current models (Go2, G1 humanoids, etc.). PoC: UniTEABag GitHub repo. Firmware pwn city.

    Post summary

    CVE-2026-1442 reveals a hardcoded TEA key in Unitree firmware, enabling attackers to decrypt, modify, and re‑sign updates. A PoC repository (UniTEABag) demonstrates the exploit, but no active exploitation or patch is reported.

    1001056
    8.4M followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-1442 (CVSS:7.8, HIGH) is Undergoing Analysis. Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an a..https://nvd.nist.gov/vuln/detail/CVE-2026-1442 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-1442 is under analysis; it involves a flaw in the encryption of firmware updates, with a CVSS score of 7.8.

    0000023
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1442 Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmwa… https://www.cve.org/CVERecord?id=CVE-2026-1442

    Post summary

    The CVE points out that the encryption algorithm protecting firmware updates relies on key material that attackers can obtain, exposing the updates to decryption. No PoC, exploit code, active exploitation, or patch details are mentioned.

    00000107
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1442 Firmware Update Encryption Bypass Vulnerability in Unitree Go2 and Product Line https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1442

    Post summary

    The entry announces CVE-2026-1442, a firmware update encryption bypass vulnerability affecting Unitree Go2 products, without providing PoC, exploit details, or patch information.

    0000039
    4.0K followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
HWunitreego1_air---
OSunitreego1_air_firmware---
HWunitreego1_pro---
OSunitreego1_pro_firmware---
HWunitreego2_air---
OSunitreego2_air_firmware---
HWunitreego2_edu_plus---
OSunitreego2_edu_plus_firmware---
HWunitreego2_edu_standard---
OSunitreego2_edu_standard_firmware---
HWunitreego2_pro---
OSunitreego2_pro_firmware---
HWunitreego2_x---
OSunitreego2_x_firmware---

Explore more