CVE-2025-60017HIGH 8.2EPSS p61.7%

CVE-2025-60017CVE-2025-60017

Description

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within restart_wifi_ap and restart_wifi_sta).

Scoring

CVSS 3.18.2 (HIGH)
VectorCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H
EPSS1.11% probability of exploitation · percentile 61.7% · 2026-06-18T12:00:27Z
Published2025-09-26
Last modified2026-04-15

Underlying weaknesses· 1

CWE-78

References

  1. https://github.com/Bin4ry/UniPwn
  2. https://news.ycombinator.com/item?id=45381590
  3. https://spectrum.ieee.org/unitree-robot-exploit

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')cwe-780%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-52688
CVE
CVE-2025-52690
CVE
CVE-2025-29063
CVE
CVE-2025-25270
CVE
CVE-2025-25053
CVE
CVE-2025-45466
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.