Back to Database
Status published
High
CVE-2025-60017
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow...
Vulnerability Description
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within restart_wifi_ap and restart_wifi_sta).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-60017
Credits & Attribution
No credits recorded in the NVD database.
References
More from Unitree
View All →CVE-2025-60251
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept...
Medium
5
CVE-2025-60250
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt...
Medium
4.7
CVE-2025-35027
Unitree Multiple Robotic Products Command Injection
High
7.3
CVE-2025-2894
Unitree Go1 Robot Dog Backdoor Control Channel
Medium
6.6
CVE-2022-2675
Unitree Go 1 "Robot Dog" Unauthenticated Remote Power Down
Medium
6.5
Affected Vendor
Unitree
View all reports →Affected Software
Go2, G1, H1, B2
Vulnerable Versions:
0
Timeline
Official Publish:
September 26th, 2025
Last Modified:
September 26th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H