CVE Vulnerabilities

CVE-2025-2894

Hidden Functionality

Published: Mar 28, 2025 | Modified: Jan 12, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Go1 also known as The Worlds First Intelligence Bionic Quadruped Robot Companion of Consumer Level, contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.

Weakness

The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product’s users or administrators.

Affected Software

NameVendorStart VersionEnd Version
Go1_firmwareUnitree- (including)- (including)

Potential Mitigations

References