PT-2025-13431 · Cloudsail+1 · Cloudsail+1

Andreas Makris

+2

·

Published

2025-03-28

·

Updated

2026-05-15

·

CVE-2025-2894

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UnitreeRobotics Zhexi/Oray (affected versions not specified)
Description The issue concerns an undocumented backdoor in the robotic device. This backdoor allows the manufacturer and anyone with the correct API key to gain complete remote control over the device using the CloudSail remote access service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Hidden Functionality

Weakness Enumeration

Related Identifiers

CVE-2025-2894

Affected Products

Cloudsail
Unitreerobotics Zhexi/Oray