CVE-2026-27510Disclosure(unitree / go2)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch unitree go2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integrity protection and validation of user-created programmes. The Android application stores programs in a local SQLite database (unitree_go2.db, table dog_programme) and transmits the programme_text content, including the pyCode field, to the robot. The robot's actuator_manager.py executes the supplied Python as root without integrity verification or content validation. An attacker with local access to the Android device can tamper with the stored programme record to inject arbitrary Python that executes when the user triggers the program via a controller keybinding, and the malicious binding persists across reboots. Additionally, a malicious program shared through the application's community marketplace can result in arbitrary code execution on any robot that imports and runs it.

4.3/ 10 priority

Sources & remediation

Exploit / PoC references
Weakness type (CWE)
CWE-345

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go2
  • go2_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 23 mentions across 12 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 11 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 20 signals
  • Disclosure: 13 classified signals
  • Peaked 11d ago at 5 mentions (2026-02-26); latest day: 1
  • 23 total mentions across 12 days

Affected systems

Vendors
Products
go2go2_firmware

1 version affected across 2 products

Deep dive

Activity timeline23 mentions / 12d
01345Mentions · 2026-02-26: 5Mentions · 2026-02-27: 5Mentions · 2026-02-28: 3Mentions · 2026-03-03: 2Mentions · 2026-03-13: 1Mentions · 2026-03-17: 1Mentions · 2026-05-14: 1Mentions · 2026-06-15: 1Mentions · 2026-07-17: 1Mentions · 2026-08-21: 1Mentions · 2026-08-27: 1Mentions · 2026-09-20: 1PoC Mentioned / Linked · 2026-02-26: 2PoC Mentioned / Linked · 2026-02-27: 1PoC Mentioned / Linked · 2026-02-28: 1PoC Mentioned / Linked · 2026-03-03: 1PoC Mentioned / Linked · 2026-03-17: 1PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-06-15: 1PoC Mentioned / Linked · 2026-07-17: 1PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-27: 1Exploit Tool / Code · 2026-02-26: 1Exploit Tool / Code · 2026-03-03: 1Exploit Tool / Code · 2026-07-17: 1Exploit Tool / Code · 2026-08-21: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-09-20: 1Technical Details · 2026-02-26: 5Technical Details · 2026-02-27: 5Technical Details · 2026-02-28: 3Technical Details · 2026-03-03: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-17: 1Technical Details · 2026-05-14: 1Technical Details · 2026-06-15: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-27: 102-2602-2702-2803-0303-1303-1705-1406-1507-1708-2108-2709-20
Signal classification5 categories
Disclosure
1356.5%
PoC
521.7%
Exploit
28.7%
General
28.7%
Patch
14.3%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-265
Disclosure2Exploit1General1PoC1
2026-02-275
Disclosure5
2026-02-283
Disclosure3
2026-03-032
Disclosure1Exploit1
2026-03-131
General1
2026-03-171
PoC1
2026-05-141
Disclosure1
2026-06-151
Disclosure1
2026-07-171
PoC1
2026-08-211
PoC1
2026-08-271
PoC1
2026-09-201
Patch1
Full discourse20 posts
  • 0xor0ne@0xor0ne
    PoC

    Reverse engineering and exploiting Unitree GO2 robots (CVE-2026-27509 / CVE-2026-27510). http://boschko.ca/unitree-go2-rce/ Research by @olivier_boschko and @ruikai #infosec https://t.co/nHEmQQ5xbU

    Post summary

    Researchers released a PoC for CVE-2026-27509 and CVE-2026-27510 targeting Unitree GO2 robots, with details linked via the provided URL.

    2170121607.7K
    93.6K followersView on X
  • Boschko@olivier_boschko
    PoC

    Discovered 2 RCEs in Unitree Go2 with @ruikai. CVE-2026-27509 is unauth'd over DDS. CVE-2026-27510 is the same sink, different source. Dropped the 32-minute technical writeup from unboxing to shells. Hope you enjoy the read! ❤️ https://boschko.ca/unitree-go2-rce

    Post summary

    The author discovered two RCEs in the Unitree Go2, provided a technical writeup with a PoC, but no patch, active exploitation, or false‑positive claim is mentioned.

    32821003910.8K
    4.3K followersView on X
  • 0xor0ne@0xor0ne
    Disclosure

    Arbitrary Python execution as root on Unitree GO2 robots via unauthenticated DDS and mobile DB tampering (CVE-2026-27509 and CVE-2026-27510) https://boschko.ca/unitree-go2-rce/ Research by @olivier_boschko and @ruikai #infosec https://t.co/jyojjlVZbr

    Post summary

    Researchers disclosed that Unitree GO2 robots can be compromised to execute arbitrary Python code as root via unauthenticated DDS and mobile DB tampering, with a PoC available at the provided link.

    017191476.7K
    88.1K followersView on X
  • 0xor0ne@0xor0ne
    PoC

    Great work by by @olivier_boschko and @ruikai about getting root RCE on Unitree GO2 robots via unauthenticated DDS and mobile DB tampering (CVE-2026-27509 and CVE-2026-27510) https://boschko.ca/unitree-go2-rce/ #infosec https://t.co/qOg7V33Idk

    Post summary

    The tweet announces a publicly available Proof of Concept that demonstrates root RCE on Unitree GO2 robots via unauthenticated DDS and mobile database tampering, with a link to detailed findings.

    09075334.9K
    88.7K followersView on X
  • 0xor0ne@0xor0ne
    Disclosure

    Root RCE on Unitree GO2 robots via unauthenticated DDS and mobile DB tampering (CVE-2026-27509 / CVE-2026-27510). Work by @olivier_boschko and @ruikai http://boschko.ca/unitree-go2-rce/ #infosec https://t.co/pC8UWRMwKp

    Post summary

    The tweet announces new root RCE CVEs on Unitree GO2 robots, linking to a PoC write‑up but offering no exploit code or evidence of live attacks.

    011067274.4K
    92.2K followersView on X
  • 0xor0ne@0xor0ne
    Disclosure

    Unauthenticated DDS access and mobile DB tampering get you root RCE on Unitree GO2 robots (CVE-2026-27509 / CVE-2026-27510). Teardown by @olivier_boschko and @ruikai http://boschko.ca/unitree-go2-rce/ #infosec https://t.co/vr376mBpNK

    Post summary

    The tweet discloses two CVEs that enable unauthenticated DDS access and database tampering to achieve root remote code execution on Unitree GO2 robots, and links to a teardown/PoC.

    212063264.8K
    93.0K followersView on X
  • /r/netsec@_r_netsec
    General

    From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510) https://boschko.ca/unitree-go2-rce/

    Post summary

    The post announces two remote code execution vulnerabilities (CVE-2026-27509 & CVE-2026-27510) affecting Unitree robots, but does not provide PoC, exploit details, or mitigation information.

    1501461.3K
    32.7K followersView on X
  • Md Ismail Šojal 🕷️@0x0SojalSec
    PoC

    From DDS Packets to Robot Shells: Two Unauthenticated root RCEs in Unitree Robots One is fully unauthenticated over the network. One requires only local database access on the companion app. - CVE-2026-27509: Unauthenticated DDS topic to arbitrary Python as root - CVE-2026-27510: Tamper the Android app’s Blockly database to same root execution path Both execute as root and persist across reboots. the complete technical analysis and public exploits & public PoCs just dropped. - http://github.com/OlivierLaflamme/UnitreeRCE

    Post summary

    The text announces two root RCE CVEs in Unitree Robots and shares a GitHub link to public PoC and exploit code, with no signs of widespread abuse or mitigation notes.

    000951.8K
    57.3K followersView on X
  • 👨‍🎤 ʐɨɢɢу@z4ziggy
    Exploit

    Unitree Go2 root exploit (CVE-2026-27510), works on 1.1.11, fixed in 1.1.13 - avoid the update to gain root 😇 https://github.com/z4ziggy/z4rtc https://t.co/4Sy3a44QAe

    Post summary

    A root exploit PoC for Unitree Go2 (CVE‑2026‑27510) is shared via GitHub; the vulnerability is fixed in firmware 1.1.13, so users are advised to avoid updating to keep exploiting the flaw.

    01072237
    1.5K followersView on X
  • 7h3h4ckv157@7h3h4ckv157
    PoC

    CVE-2026-27509 Unauthenticated DDS-Based Remote Code Execution & CVE-2026-27510 Mobile Database Tampering Leading to Remote Code Execution Cool work by @olivier_boschko Read: https://boschko.ca/unitree-go2-rce https://t.co/JTZ4ZUtm7U

    Post summary

    The message promotes two CVEs with a link to a blog that likely contains proof‑of‑concept details, but does not discuss active exploitation, patches, or debunking.

    020232.2K
    57.1K followersView on X
  • yousukezan@yousukezan
    Exploit

    Unitree社の四足歩行ロボットGo2に2件のリモートコード実行(RCE)脆弱性(CVE-2026-27509、CVE-2026-27510)が存在した。両脆弱性とも設計上の認証・検証不足に起因し、ロボットを完全に制御される重大な問題である。 最初の脆弱性は、DDS(Data Distribution Service)通信に認証が実装されていない点を悪用するものだ。攻撃者は同一ネットワーク上から特定のDDSトピックに細工したメッセージを送信し、Pythonコードをアップロードできる。さらに、そのコードをコントローラーの特定キー(例:R1+Y)に紐づけることで、ボタン操作をきっかけに任意コードをroot権限で実行させられる。コードはロボット内部に保存されるため、再起動後も持続するバックドアとなる。 二つ目の脆弱性は、ファームウェア更新後にDDSトピックの列挙が制限された環境下でも成立する。公式AndroidアプリのローカルSQLiteデータベース内に保存されるプログラム情報を改ざんし、Pythonコード部分(pyCode)を書き換えることで、同様に任意コード実行が可能となる。ユーザーはアプリ上でプログラムをキーに割り当てるだけで、改ざん済みコードが実行される。 https://boschko.ca/unitree-go2-rce/

    Post summary

    Two RCE flaws in Unitree Go2 robots let attackers upload and run arbitrary Python code via DDS messages or Android app database edits, granting persistent root-level control.

    020501.3K
    11.6K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510) https://boschko.ca/unitree-go2-rce/

    Post summary

    Two remote code execution vulnerabilities have been disclosed for Unitree robots, identified as CVE-2026-27509 and CVE-2026-27510.

    00021909
    151.7K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-27509 Unauthenticated DDS-Based Remote Code Execution CVE-2026-27510 Mobile Database Tampering Leading to Remote Code Execution From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510) https://boschko.ca/unitree-go2-rce/

    Post summary

    The text announces the discovery of two unauthenticated remote code execution vulnerabilities in Unitree robots, providing a link that likely contains detailed PoC information, but it does not mention active exploitation, patches, or exploit tools.

    00011376
    6.7K followersView on X
  • Smurfs ✘@0xsmurfsr
    Disclosure

    Unitree GO2 ที่เป็นหุ่นยนต์หมาหน้าตาโง่ๆมีช่องโหว่อันตรายมาก (CVE-2026-27510) ที่อนุญาติให้คนอื่นสามารถข้ามการยืนยันตัวตนความเป็นเจ้าของได้ แล้วพอไม่ต้องยืนยันตัวตนมันทำให้คนที่เจาะเข้ามาสามารถรัน Code ภายในตัวหุ่นยนต์ได้อาจจะเป็นดูกล้องและสามารถดูข้อมูลการใช้งานของหุ่นยนต์ได้ว่าแต่ละวันได้รับคำสั่งอะไรจากเจ้าของตัวจริงซึ่งโคตรน่ากลัวเลยอันนี้

    Post summary

    The post announces CVE-2026-27510 for Unitree GO2, detailing an authentication bypass that permits code execution and camera access, but offers no proof of exploitation or mitigation.

    10000157
    312 followersView on X
  • Francesco Pira@pirafrank
    Patch

    That is a strong wormable-style primitive, although the researchers did not demonstrate self-propagation. Unitree shipped fixes in v1.1.13 for CVE-2026-27510. https://boschko.ca/unitree-go2-rce/

    Post summary

    The text reports that Unitree has released a fix (version v1.1.13) for CVE‑2026‑27510, addressing a wormable‑style RCE primitive.

    0000047
    715 followersView on X
  • DailyCVE@dailycve
    General

    🟠 Unitree Go2, Remote Code Execution, #CVE-2026-27510 (MEDIUM) https://dailycve.com/unitree-go2-remote-code-execution-cve-2026-27510-medium/

    Post summary

    The post references CVE‑2026‑27510 as an RCE vulnerability with MEDIUM severity, but offers no PoC, exploit, or mitigation details.

    0000040
    168 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27510 (CVSS:6.4, CRITICAL) is Awaiting Analysis. Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.dogg..https://nvd.nist.gov/vuln/detail/CVE-2026-27510 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A critical vulnerability (CVE-2026-27510) affecting Unitree Go2 firmware 1.1.7‑1.1.11 and its Android app is identified, but no exploit, patch, or active exploitation details are provided.

    0000038
    173 followersView on X
  • CybrPulse@CybrPulse
    Disclosure

    Two RCEs just dropped for Unitree Go2 robots. Unauthenticated remote code execution on a quadrupedal robot. That's... not great. CVE-2026-27509 & CVE-2026-27510 https://boschko.ca/unitree-go2-rce/

    Post summary

    Two new unauthenticated remote code execution vulnerabilities (CVE-2026-27509 & CVE-2026-27510) have been disclosed for Unitree Go2 robots, with details posted on a blog.

    0000040
    16 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27510 - Critical Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integri... https://www.thehackerwire.com/vulnerability/CVE-2026-27510/ https://t.co/E1OLqMLKxN

    Post summary

    The post announces a critical remote code execution vulnerability in Unitree Go2 firmware (v1.1.7–1.1.11) when paired with the Android app, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000064
    119 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27510 Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution d… https://www.cve.org/CVERecord?id=CVE-2026-27510 ----- Traducción: CVE-2026-27510 las… http://infoflow.cloud`

    Post summary

    CVE‑2026‑27510 is a remote code execution flaw affecting Unitree Go2 firmware 1.1.7‑1.1.11 when paired with the Android app, with a CVE record link but no PoC, exploit, or patch details.

    0000053
    55 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWunitreego2---
OSunitreego2_firmware---

Explore more