RobotRisk Autonomous Systems Incident & Risk Register
RobotRiskUnitree › 21 Mar 2025

Backdoor (CVE-2025-2894) found in Unitree Go1 robot firmware

S2 · 21 Mar 2025 · Unitree

Record

CompanyUnitree
IndustryHumanoid robots
Type(s)cyber
Date21 Mar 2025 (day precision)
Time of daynot documented
Locationno physical site (recall / fleet-wide / aggregate record)
Severity (minor injury or single-unit damage)
Scalefleet-wide (Go1 model)
Confidencehigh
Verified flagCited source on file; not independently re-verified

Summary

Security researchers disclosed a firmware backdoor in Unitree's Go1 quadruped that auto-started on boot, tunneled to a China-based cloud server, and gave anyone with the right API key full remote control; vulnerable units were confirmed operating on networks at MIT, Princeton, Carnegie Mellon and the University of Waterloo.

Primary source

OECD.AI Incident Monitor

Publisher: OECD.AI Incident Monitor · Retrieved: 2026-09-16

Supporting source rows (1)
DateSupporting source rowPublisherLink
21 Mar 2025 Backdoor (CVE-2025-2894) found in Unitree Go1 robot firmware OECD.AI Incident Monitor OECD.AI Incident Monitor

Unitree other incidents timeline

Humanoid robots context

cyber context

Unitree industry position

Related incidents

Other Unitree entries

Report a correction

Open a prefilled GitHub issue

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs