Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within restart_wifi_ap and restart_wifi_sta).
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 26 Sep 2025 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 26 Sep 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within restart_wifi_ap and restart_wifi_sta). | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-26T04:21:00.741Z
Reserved: 2025-09-23T00:00:00.000Z
Link: CVE-2025-60017

No data.

Status : Received
Published: 2025-09-26T01:15:36.883
Modified: 2025-09-26T05:15:36.337
Link: CVE-2025-60017

No data.

No data.