RobotRisk Autonomous Systems Incident & Risk Register
RobotRisk / Unitree /

Backdoor (CVE-2025-2894) found in Unitree Go1 robot firmware

S2 · · Unitree

Record

CompanyUnitree
Categoryhumanoid
Typecyber
Date
Time of daynot documented
Locationno physical site (recall / fleet-wide / aggregate record)
SeverityS2 (minor injury or single-unit damage)
Scalefleet-wide (Go1 model)
Confidencehigh
VerificationCited source on file; not independently re-verified
SourceOECD.AI Incident Monitor

What happened

Security researchers disclosed a firmware backdoor in Unitree's Go1 quadruped that auto-started on boot, tunneled to a China-based cloud server, and gave anyone with the right API key full remote control; vulnerable units were confirmed operating on networks at MIT, Princeton, Carnegie Mellon and the University of Waterloo.

Unitree record context

Entries by year and severity

232025 S1: 22025 S2: 13252026 S1: 12026 S3: 1226
S1S2S3S4S5

By incident type

By severity

Unitree vs humanoid alternatives

humanoid context

humanoid: entries by year

482017 S1: 11172024 S1: 11242025 S1: 22025 S2: 12025 S3: 12025 S5: 48252026 S1: 12026 S3: 1226
S1S2S3S4S5

humanoid: failure modes

humanoid: most entries

cyber context

cyber: by category

cyber: by year

cyber: severity profile

Comparable cyber events in humanoid

SevDateCompanyEvent
S12026-08-27UnitreeTwo root RCE flaws (CVE-2026-76639/76640) disclosed in Unitree G1 EDU
S12025-10UnitreeUnauthenticated RCE flaws (CVE-2026-27509, CVE-2026-27510) found in Unitree Go2
S22025-09UnitreeUniPwn wormable Bluetooth exploit roots Unitree Go2, B2, G1 and H1

Other Unitree entries

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs