S1 · 10/2025 · Unitree
| Company | Unitree |
| Category | humanoid |
| Type | cyber |
| Date | 10/2025 |
| Time of day | not documented |
| Location | no physical site (recall / fleet-wide / aggregate record) |
| Severity | S1 (near-miss / disclosed vulnerability) |
| Scale | fleet-wide (Go2 model, firmware V1.1.7/V1.1.11) |
| Confidence | high |
| Verification | Cited source on file; not independently re-verified |
| Source | boschko.ca (independent researcher writeup) |
A researcher disclosed two unauthenticated remote-code-execution vulnerabilities in the Unitree Go2 quadruped's actuator control system, one abusing a DDS DataWriter to run arbitrary Python as root and one tampering with pre-programmed Blockly action data stored in the companion Android app.