The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 03 Apr 2025 14:45:00 +0000


Fri, 28 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 03:15:00 +0000

Type Values Removed Values Added
Description The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.
Title Unitree Go1 Robot Dog Backdoor Control Channel
Weaknesses CWE-912
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AHA

Published:

Updated: 2025-04-03T14:37:08.450Z

Reserved: 2025-03-28T00:53:27.892Z

Link: CVE-2025-2894

cve-icon Vulnrichment

Updated: 2025-03-28T15:41:22.659Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-28T03:15:18.780

Modified: 2025-04-03T15:15:48.053

Link: CVE-2025-2894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.