PT-2026-22294 · Unitree · Unitree Go2

·

CVE-2026-1442

·

Published

2026-02-27

·

Updated

2026-03-11

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Unitree Go2 and other models versions (affected versions not specified)
Description The encryption algorithm used to protect firmware updates is encrypted using key material accessible to attackers. This allows unauthorized modification of firmware updates, which can then be trusted by Unitree products. The issue affects the firmware generation and extraction processes. Currently, there is no publicly documented method to bypass the update process and inject malicious firmware packages without the owner's knowledge.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1442

Affected Products

Unitree Go2