PT-2026-22294 · Unitree · Unitree Go2
Todb
·
Published
2026-02-27
·
Updated
2026-03-11
·
CVE-2026-1442
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Unitree Go2 and other models versions (affected versions not specified)
Description
The encryption algorithm used to protect firmware updates is encrypted using key material accessible to attackers. This allows unauthorized modification of firmware updates, which can then be trusted by Unitree products. The issue affects the firmware generation and extraction processes. Currently, there is no publicly documented method to bypass the update process and inject malicious firmware packages without the owner's knowledge.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unitree Go2