RobotRisk Autonomous Systems Incident & Risk Register
RobotRiskUnitree › ~Oct 2025

Unauthenticated RCE flaws (CVE-2026-27509, CVE-2026-27510) found in Unitree Go2

S1 · ~Oct 2025 · Unitree

Record

CompanyUnitree
IndustryHumanoid robots
Type(s)cyber
Date~Oct 2025 (month precision)
Time of daynot documented
Locationno physical site (recall / fleet-wide / aggregate record)
Severity (near-miss / disclosed vulnerability)
Scalefleet-wide (Go2 model, firmware V1.1.7/V1.1.11)
Confidencehigh
Verified flagCited source on file; not independently re-verified

Summary

A researcher disclosed two unauthenticated remote-code-execution vulnerabilities in the Unitree Go2 quadruped's actuator control system, one abusing a DDS DataWriter to run arbitrary Python as root and one tampering with pre-programmed Blockly action data stored in the companion Android app.

Primary source

boschko.ca (independent researcher writeup)

Publisher: boschko.ca (independent researcher writeup) · Retrieved: 2026-09-16

Supporting source rows (1)
DateSupporting source rowPublisherLink
~Oct 2025 Unauthenticated RCE flaws (CVE-2026-27509, CVE-2026-27510) found in Unitree Go2 boschko.ca (independent researcher writeup) boschko.ca

Unitree other incidents timeline

Humanoid robots context

cyber context

Unitree industry position

Related incidents

Other Unitree entries

Report a correction

Open a prefilled GitHub issue

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs