Public model · open registry · v1.0-candidate

Trace the exploit to the consequence that matters.

A severity score describes an exploit. A consequence path explains what that exploit can reach: the authority crossed, the capability gained, the people or systems affected, and what recovery actually takes.

Candidate, not canon. Every record exposes its evidence, inferences, assumptions, and open review state.

The model, not just the score

The reasoning is the public artifact.

Each transition declares whether it comes from a source, a model inference, or an operational assumption. That makes disagreement local and actionable.

One record, made inspectable

How a local foothold becomes a fleet consequence

CPATH-2026-0023 · Unitree

EMERGENCY
  1. accessSource-backed

    Seed robot compromised over BLE

    The cited records describe BLE-adjacent access that can cross the shared-key authentication boundary and obtain root on an affected seed robot.

    Evidence: NVD · NVD

  2. boundarySource-backed

    Reusable peer propagation

    The research record describes a compromised robot scanning for in-range peers and reusing the shared key to infect them; this is peer propagation across nearby robots, not proof of Unitree cloud control.

    Evidence: NVD · NVD · NVD

  3. capabilityModel inference

    Repeatable root across peers

    Automated peer scanning removes the need for the attacker to approach every robot personally, so the model assigns fleet-scale reuse and execution to an in-range deployment.

  4. consequenceModel inference

    Fleet control plane

    Repeated root compromise can aggregate control, sensing access, and safety exposure across multiple mobile robots. EMERGENCY denotes that reachable deployment consequence, not confirmed exploitation in the field.

  5. recoveryOperational assumption

    Fleet-wide remediation

    Recovery requires fleet-wide firmware remediation and coordinated verification because any unpatched peer left in range can preserve the propagation condition.

Why this path dominates

The fleet-control-plane path is dominant because documented peer scanning can reuse the shared key across in-range robots, producing the only fleet-scale EMERGENCY path; motion and privacy remain supporting CRITICAL paths.

Inspect the full record

Reference cases

Three ways a headline score can hide the real question.

These hand-authored paths anchor the public quality bar: under-scoring scale, missing a privacy-to-authority transition, and over-claiming from a control absence.

Corpus health

Coverage before confidence.

40
public records with explicit paths
35/40
records with complete source-link coverage
0
records independently path-reviewed

All records are published as provisional candidates. Coverage describes what is inspectable; it is not an accuracy claim.

Complete public corpus

Explore consequence paths.

Search the entire server-rendered registry, then narrow by consequence family, domain, or candidate band. The URL preserves the view you create.

Consequence family

40 of 40 records

Every result below is in the initial HTML; filters only change the view.

RecordProduct and pathDomainCandidate bandPublished baseline
CPATH-2026-0001Qardio Arm blood-pressure monitor + iOS appQardioAccount authorityWearable healthCRITICALCVSS 6.6 MEDIUM
CPATH-2026-0002Baxter Life2000 Ventilation System + Service PCBaxter (vendor self-disclosure)Observability and recoveryMedical IoTMONITORCVSS 10 CRITICAL
CPATH-2026-0003Contec CMS8000 patient monitorContec (also sold under rebrands)Firmware trust root · Device-control safety · Data privacyMedical IoTCRITICALCVSS 8.2 HIGH
CPATH-2026-0004Baxter Life2000 internal JTAG flash R/WBaxterDevice-control safety · Firmware trust rootMedical IoTCRITICALCVSS 9.3 CRITICAL
CPATH-2026-0005Baxter Life2000 hard-coded clinician credentialsBaxterAccount authorityMedical IoTCRITICALCVSS 9.3 CRITICAL
CPATH-2026-0006Contec CMS8000 out-of-bounds write via UDPContecDevice-control safety · Device availability and recoveryMedical IoTEMERGENCYCVSS 9.8 CRITICAL
CPATH-2026-0007Qardio BLE unauthenticated DoS (startMeasurement flood)QardioDevice availability and recoveryWearable healthELEVATEDCVSS 7.1 HIGH
CPATH-2026-0008Qardio firmware files extractableQardioData privacyWearable healthHIGHCVSS 6.9 MEDIUM
CPATH-2026-0009Swisslog Translogic PTS unsigned firmware updateSwisslogFirmware trust root · Fleet control planeGeneral IoTEMERGENCYCVSS 9.8 CRITICAL
CPATH-2026-0010Swisslog Translogic TLP20 tcpTxThread stack overflowSwisslogDevice-control safety · Device availability and recoveryGeneral IoTCRITICALCVSS 9.8 CRITICAL
CPATH-2026-0011SideQuest deep-link one-click RCE on Oculus Quest sideloading platform (CVE-2024-21625)MetaPerception-to-action · Account authoritySmart glasses / ARCRITICALCVSS 8.8 HIGH
CPATH-2026-0012Inception Attack: malicious VR app hijacks the entire Meta Quest environment (UChicago, 2024)MetaPerception-to-action · Perception privacySmart glasses / ARCRITICALNo published baseline
CPATH-2026-0013Apple Vision Pro (visionOS · Persona avatar)ApplePerception privacy · Account authoritySmart glasses / ARCRITICALCVSS 5.3 MEDIUM
CPATH-2026-0014HoloLens Broadcom Wi-Fi over-the-air RCE/DoS (ADV190017: CVE-2019-9501/9503)MicrosoftDevice-control safetySmart glasses / ARCRITICALCVSS 8.8 HIGH
CPATH-2026-0015HoloLens Device Portal pairing-API unauthenticated DoS (CVE-2024-57972)MicrosoftDevice availability and recoverySmart glasses / ARCRITICALCVSS 6.5 MEDIUM
CPATH-2026-0016Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021)MetaPerception privacySmart glasses / ARCRITICALNo published baseline
CPATH-2026-0017PX4 Autopilot MAVLink Unauthenticated Remote Shell (CVE-2026-1579)PX4 / DronecodeDevice-control safetyDrone / autonomous systemsEMERGENCYCVSS 9.8 CRITICAL
CPATH-2026-0018Tesla Model 3 VCSEC TPMS Integer Overflow RCE (CVE-2025-2082)TeslaPerception-to-actionDrone / autonomous systemsCRITICALCVSS 7.5 HIGH
CPATH-2026-0019Tesla Model 3 Gateway Firmware Signature-Bypass / TOCTTOU Code Execution (CVE-2023-32156)TeslaDevice-control safety · Firmware trust rootDrone / autonomous systemsCRITICALCVSS 9 CRITICAL
CPATH-2026-0020DJI Mavic 3 Wi-Fi Weak Credentials / QuickTransfer Key Derivation (CVE-2023-6951)DJIPerception privacyDrone / autonomous systemsCRITICALCVSS 6.6 MEDIUM
CPATH-2026-0021Phantom of the ADAS: Projected/Billboard Phantom Object Attacks on Tesla Autopilot and MobileyeTeslaDevice-control safety · Perception-to-actionDrone / autonomous systemsCRITICALNo published baseline
CPATH-2026-0022GPS/GNSS Spoofing Safe-Hijacking of Consumer Drones (Adaptive GPS Spoofing / Tractor Beam class)GNSS (multi-vendor)Perception-to-action · Device-control safetyDrone / autonomous systemsCRITICALNo published baseline
CPATH-2026-0023Unitree UniPwn — BLE Wi-Fi config root takeover (Go2/B2/G1/H1)UnitreeFleet control planeRobotics / humanoidEMERGENCYCVSS 8.2 HIGH
CPATH-2026-0024Unitree Go2 unauthenticated DDS RCE via programming_actuator topic (CVE-2026-27509)UnitreeDevice-control safety · Perception privacyRobotics / humanoidCRITICALCVSS 8.5 HIGH
CPATH-2026-0025Unitree Go2 Android-app database tampering RCE (CVE-2026-27510)UnitreePerception privacyRobotics / humanoidCRITICALCVSS 9.6 CRITICAL
CPATH-2026-0026Unitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894)UnitreeDevice-control safety · Fleet control planeRobotics / humanoidEMERGENCYCVSS 6.6 MEDIUM
CPATH-2026-0027Universal Robots PolyScope 5 Dashboard Server OS command injection (CVE-2026-8153)Universal RobotsDevice-control safety · Fleet control plane · Account authorityRobotics / humanoidEMERGENCYCVSS 9.8 CRITICAL
CPATH-2026-0028Teleoperated surgical robot (Raven II) command hijacking & E-stop abuseUniversity of Washington (Raven II)Perception-to-action · Device-control safety · Device availability and recoveryRobotics / humanoidCRITICALNo published baseline
CPATH-2026-0029Hikvision IP camera / NVR unauthenticated command injection (CVE-2021-36260)HikvisionPerception-to-action · Account authority · Fleet control planeGeneral IoTEMERGENCYCVSS 9.8 CRITICAL
CPATH-2026-0030Dahua IP camera / VTH / VTO authentication bypass (CVE-2021-33044)DahuaDevice-control safety · Account authorityGeneral IoTEMERGENCYCVSS 9.8 CRITICAL
CPATH-2026-0031TP-Link Archer AX21 (AX1800) router unauthenticated command injection (CVE-2023-1389)TP-LinkAccount authority · Fleet control planeGeneral IoTEMERGENCYCVSS 8.8 HIGH
CPATH-2026-0032Moxa PT/EDS industrial Ethernet switch authentication bypass (CVE-2024-12297)MoxaAccount authority · Device availability and recovery · Data privacyGeneral IoTHIGHCVSS 9.2 CRITICAL
CPATH-2026-0033Chirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197)Chirp SystemsAccount authority · Device-control safetyGeneral IoTHIGHCVSS 4.3 MEDIUM
CPATH-2026-0034August Smart Lock Pro + Connect Wi-Fi password disclosure via hardcoded key (CVE-2019-17098)AugustData privacyGeneral IoTHIGHCVSS 6.5 MEDIUM
CPATH-2026-0035Medtronic Conexus RF telemetry protocol lacks authentication/encryption (implantable cardiac devices)MedtronicDevice-control safety · Data privacyMedical IoTCRITICALCVSS 9.3 CRITICAL
CPATH-2026-0036Medtronic MiniMed 508 / Paradigm insulin pumps - unauthenticated RF allows insulin delivery controlMedtronicDevice-control safety · Data privacyMedical IoTCRITICALCVSS 8.8 HIGH
CPATH-2026-0037Medtronic MiniMed / NGP 600 series insulin pumps - RF pairing protocol allows bolus/delivery manipulationMedtronicDevice-control safetyMedical IoTCRITICALCVSS 4.8 MEDIUM
CPATH-2026-0038GE CARESCAPE / ApexPro patient monitoring (MDhex) - exposed shared SSH private keyGE HealthCarePerception-to-action · Device-control safetyMedical IoTEMERGENCYCVSS 10 CRITICAL
CPATH-2026-0039Baxter Sigma Spectrum WBM - cleartext Wi-Fi credentials and PHIBaxterAccount authority · Data privacyMedical IoTHIGHCVSS 4.2 MEDIUM
CPATH-2026-0040B. Braun Infusomat/Perfusor Space (SpaceCom2 / Battery pack SP with Wi-Fi) - remote unauthenticated dose alterationB. BraunDevice-control safety · Data privacyMedical IoTCRITICALCVSS 10 CRITICAL