CVE-2026-27510 - Vulnerability Analysis
CriticalCVSS: 9.6Last Updated: February 27, 2026
Unitree Go2 - Remote Code Execution
Overview
Unitree Go2 firmware 1.1.7 through 1.1.11 with Unitree Go2 Android app contains a remote code execution vulnerability caused by missing integrity checks on user-created programs executed as root, letting attackers execute arbitrary Python code remotely or locally via tampered programs.
Severity & Score
Impact
Attackers can execute arbitrary code as root on the robot, leading to full system compromise.
Mitigation
Update Unitree Go2 firmware to a version later than 1.1.11 and update the Android application to the latest version with integrity checks.
References
Social Media Activity(2 posts)
From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510) https://boschko.ca/unitree-go2-rce/
View original postFrom DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510) https://boschko.ca/unitree-go2-rce/
View original postRelated Resources
Details
- CVE ID
- CVE-2026-27510
- Severity
- Critical
- CVSS Score
- 9.6
- Type
- remote_code_execution
- Status
- unconfirmed
- EPSS
- 0.0%
- Social Posts
- 2
CWE
- CWE-345
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H