CVE-2026-1442 describes a critical vulnerability in Unitree products, including the Go2, where firmware updates are protected by an encryption algorithm whose key material is publicly accessible. This allows unauthorized alteration of firmware, which Unitree products would then trust. With a CVSS score of 7.8 (High), this local attack vector requires user interaction but can lead to high impact on confidentiality, integrity, and availability. While there is no publicly documented mechanism for subverting the update process without the equipment owner's knowledge, there are no known exploits or active exploitation, though the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:unitree:go2_edu_plus_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:unitree:go1_pro_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:unitree:go1_air_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:unitree:go2_x_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:unitree:go2_pro_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.