RobotRisk Autonomous Systems Incident & Risk Register
RobotRisk / Unitree / 2025-09

UniPwn wormable Bluetooth exploit roots Unitree Go2, B2, G1 and H1

S2 · 09/2025 · Unitree

Record

CompanyUnitree
Categoryhumanoid
Typecyber
Date09/2025
Time of daynot documented
Locationno physical site (recall / fleet-wide / aggregate record)
SeverityS2 (minor injury or single-unit damage)
Scalefleet-wide (Go2, B2, G1, H1 models)
Confidencehigh
VerificationCited source on file; not independently re-verified
SourceThe Robot Report

What happened

Researchers disclosed 'UniPwn,' a Bluetooth Low Energy exploit giving root-level access to Unitree Go2/B2 quadrupeds and G1/H1 humanoids; the flaw is wormable, letting a compromised robot automatically scan for and infect nearby Unitree units.

Unitree record context

Entries by year and severity

232025 S1: 22025 S2: 13252026 S1: 12026 S3: 1226
S1S2S3S4S5

By incident type

By severity

Unitree vs humanoid alternatives

humanoid context

humanoid: entries by year

482017 S1: 11172024 S1: 11242025 S1: 22025 S2: 12025 S3: 12025 S5: 48252026 S1: 12026 S3: 1226
S1S2S3S4S5

humanoid: failure modes

humanoid: most entries

cyber context

cyber: by category

cyber: by year

cyber: severity profile

Comparable cyber events in humanoid

SevDateCompanyEvent
S12026-08-27UnitreeTwo root RCE flaws (CVE-2026-76639/76640) disclosed in Unitree G1 EDU
S12025-10UnitreeUnauthenticated RCE flaws (CVE-2026-27509, CVE-2026-27510) found in Unitree Go2
S2UnitreeBackdoor (CVE-2025-2894) found in Unitree Go1 robot firmware

Other Unitree entries

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs