CPATH-2026-0023 · Robotics / humanoid

Unitree UniPwn — BLE Wi-Fi config root takeover (Go2/B2/G1/H1)

A dominant fleet control plane path connects the public security record to a provisional EMERGENCY consequence band.

Candidate bandEMERGENCY
Dominant pathFleet control plane

The fleet-control-plane path is dominant because documented peer scanning can reuse the shared key across in-range robots, producing the only fleet-scale EMERGENCY path; motion and privacy remain supporting CRITICAL paths.

Causal model

What has to happen for this consequence to hold?

3 candidate paths · explicit source, inference, and assumption boundaries.

Systemic · Dominant path

Fleet control plane

A compromised robot can scan for in-range peers and reuse the shared key, turning local root entry into repeatable deployment propagation.

EMERGENCY
  1. accessSource-backed

    Seed robot compromised over BLE

    The cited records describe BLE-adjacent access that can cross the shared-key authentication boundary and obtain root on an affected seed robot.

    EvidenceNVD · NVD

  2. boundarySource-backed

    Reusable peer propagation

    The research record describes a compromised robot scanning for in-range peers and reusing the shared key to infect them; this is peer propagation across nearby robots, not proof of Unitree cloud control.

    EvidenceNVD · NVD · NVD

  3. capabilityModel inference

    Repeatable root across peers

    Automated peer scanning removes the need for the attacker to approach every robot personally, so the model assigns fleet-scale reuse and execution to an in-range deployment.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Fleet control plane

    Repeated root compromise can aggregate control, sensing access, and safety exposure across multiple mobile robots. EMERGENCY denotes that reachable deployment consequence, not confirmed exploitation in the field.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet-wide remediation

    Recovery requires fleet-wide firmware remediation and coordinated verification because any unpatched peer left in range can preserve the propagation condition.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

One robot must first be reached over BLE; an infected robot can then scan for nearby peers and reuse the shared key without further attacker proximity.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

The published proof of concept automates peer discovery and reuse of the shared key after the first robot is compromised.

Source-backedNVD
ExposureEX 2
Access position limits exposure

Initial access remains limited to BLE range even though an infected robot can automate propagation to nearby peers.

Model inference
Consequence
Physical / safetyPH 3
Credible safety consequence

Aggregate of many root-controlled mobile robots reduces safety margin across a deployment.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Operational or firmware state across fleet.

Model inference
AuthorityAT 3
Administrative or command authority

Root authority on each peer (not firmware-update or signing-root).

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Multi-hop reusable cross-domain bridge.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

(shared key across entire population).

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

After one nearby robot is compromised, automated scanning and the shared key let it approach additional in-range peers without the attacker visiting each one.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Every affected robot needs patched firmware and coordinated verification because one unpatched peer can preserve the nearby propagation path.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Active
Active condition at scoring time

The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it. This status is recorded for Unitree UniPwn.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. Systemic uplift

    The CRITICAL base band rises to EMERGENCY because a compromised robot can scan for peers and reuse the shared key, while recovery must cover every reachable robot in the deployment.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:2/EC:4/EX:2/PH:3/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:3/LS:ACTIVERead the scoring method →

Perception · Supporting path

Perception-to-action

BLE-proximity root authority reaches the perception and motion stack of a mobile robot, creating a modeled embodied-safety path.

CRITICAL
  1. accessSource-backed

    BLE-proximity entry

    The cited CVE records place initial access within BLE proximity or adjacent range of an affected Unitree robot.

    EvidenceNVD · NVD · NVD · NVD

  2. boundarySource-backed

    Shared key to root

    The documented chain combines a shared hardcoded key, weak string authentication, and sudo command injection to cross from BLE setup access to root authority.

    EvidenceNVD · NVD

  3. capabilityModel inference

    Root reaches the embodied stack

    Root authority can reach onboard perception inputs and the motion stack; that is the modeled transition from device compromise to perception-informed actuation.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Mobile-robot safety consequence

    Unauthorized control of the motion stack on a walking mobile robot can create physical or bystander safety consequences. This is a capability-grounded candidate path; the sources do not establish weaponized motion or field harm.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Per-unit embodied recovery

    This path assumes BLE proximity for initial actuation control and vendor firmware remediation with per-unit verification; it does not inherit fleet propagation automatically.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

The initial attacker must be within BLE range; the shared key and weak authentication then expose the root command path without a prior account.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

The published proof of concept combines the shared BLE key, weak string authentication, and command injection into a reproducible root workflow.

Source-backedNVD
ExposureEX 2
Access position limits exposure

The root workflow is reproducible, but the attacker still has to begin within BLE range of an affected robot.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

A compromised robot can issue motion commands to peers, creating a credible risk of collision or unsafe movement around people.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

Onboard perception (LIDAR or spatial map or camera) drives the robot's own actuation, so perception feeds action (the perception-to-action link).

Model inference
AuthorityAT 3
Administrative or command authority

The reused fleet key grants command authority over reachable robots without exposing the vendor’s firmware-signing root.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Crosses RF to device to physical or safety boundaries.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

Shared key reuses across population.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

Initial motion control remains limited to one robot within BLE range; automated peer propagation is assessed in the separate fleet path.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Vendor firmware fix needed but per-unit, not a recall or signing-root rotation.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Active
Active condition at scoring time

The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it. This status is recorded for Unitree UniPwn.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Onboard perception (LIDAR or spatial map or camera) drives the robot's own actuation, so perception feeds action (the perception-to-action link).

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:2/EC:4/EX:2/PH:4/DP:4/AT:3/CH:4/SR:4/SX:2/OR:3/EV:3/LS:ACTIVERead the scoring method →

Privacy · Supporting path

Perception privacy

Root access exposes live camera and microphone streams, LIDAR output, and spatial maps that describe the robot's surroundings.

CRITICAL
  1. accessSource-backed

    Proximity or local access

    The attacker first obtains root from within BLE range using the same shared-key weakness as the motion-control path.

    EvidenceNVD

  2. boundaryModel inference

    Reusable multi-stage bridge

    BLE entry crosses into the robot operating system and then into live sensing and stored spatial state.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Safety-driving perception or intimate data

    Root access exposes live camera and microphone streams, LIDAR output, and spatial maps that describe the robot's surroundings.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Perception privacy

    Root access exposes live camera and microphone streams, LIDAR output, and spatial maps that describe the robot's surroundings.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Affected robots need the vendor firmware fix and per-unit verification that the shared-key entry path is closed.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

The attacker first obtains root from within BLE range using the same shared-key weakness as the motion-control path.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

The published root workflow already exposes the robot operating system; opening camera, microphone, LIDAR, or map data requires no separate exploit.

Source-backedNVD
ExposureEX 2
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 0
No direct physical effect

This privacy path concerns surveillance through robot sensors; any physical hazard from root-controlled motion is assessed in the separate safety path.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

Root access exposes live camera and microphone streams, LIDAR output, and spatial maps that describe the robot's surroundings.

Model inference
AuthorityAT 3
Administrative or command authority

The attacker holds operating-system root while collecting sensor data; the path does not claim control of a vendor signing key.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

BLE entry crosses into the robot operating system and then into live sensing and stored spatial state.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The shared BLE key and root workflow can be reused across affected robot models.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

Sensor collection is available on each compromised robot, while initial access to this path remains proximity-bound.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Affected robots need the vendor firmware fix and per-unit verification that the shared-key entry path is closed.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Active
Active condition at scoring time

The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Root access exposes live camera and microphone streams, LIDAR output, and spatial maps that describe the robot's surroundings.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:4/AT:3/CH:3/SR:4/SX:2/OR:3/EV:3/LS:ACTIVERead the scoring method →

Triage implication

Verify the systemic transition before acting on the band.

Triage beyond the first device: verify whether the reusable condition, propagation mechanism, and recovery dependency actually exist across the deployment.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 7.3 HIGHTakeonme CNA via NVD (CVE-2025-35027)
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
v3.1 · 8.2 HIGHMITRE via NVD (CVE-2025-60017)
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H
v3.1 · 4.7 MEDIUMMITRE via NVD (CVE-2025-60250)
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
v3.1 · 5 MEDIUMMITRE via NVD (CVE-2025-60251)
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Unitree UniPwn — BLE Wi-Fi config root takeover (Go2/B2/G1/H1) at EMERGENCY — the worst of 3 risk paths (perception, authority). The dominant consequence is reach into a fleet management plane.

Vulnerability

Unitree UniPwn — BLE Wi-Fi config root takeover (Go2/B2/G1/H1). Reported attack vector: Adjacent (Bluetooth/BLE proximity).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

PERCEPTION_TO_ACTIONCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:2/EC:4/EX:2/PH:4/DP:4/AT:3/CH:4/SR:4/SX:2/OR:3/EV:3/LS:ACTIVE

Exposure EX=2 (reachability-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=HIGH → base CRITICAL → assessed CRITICAL.

  • BLE-proximity (RE2) unauthenticated root via hardcoded key + trivial string-auth + sudo command injection (EC4, public PoC). Root grants full control of the motion stack of a walking humanoid/quadruped: credible physical hazard to bystanders (PH4). Onboard perception (LIDAR/spatial map/camera) drives the robot’s own actuation, so perception feeds action (DP4, perception_feeds_action).
  • AT3 — full OS/service authority but not a signing-root/OTA-root. Crosses RF->device->physical/safety boundaries (CH4, boundary_crossing).
  • SR4 — shared key reuses across population;
  • SX2 — per-device proximity for the initial actuation control.
  • OR3 — vendor firmware fix needed but per-unit, not a recall/signing-root rotation.
  • EV3 — reproduced; no published weaponized-motion demo so active_exploitation=false.

FLEET_CONTROL_PLANEEMERGENCY

CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:2/EC:4/EX:2/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:3/LS:ACTIVE

Exposure EX=2 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.

  • Wormable: a compromised robot autonomously scans BLE and infects in-range Unitree units using the same hardcoded shared key, forming a robot botnet. Initial entry is BLE-proximity (RE2) but propagation is self-spreading and key-portable, so SX4 (fleet/deployment-scale propagation without per-device human access by the attacker), SR4 (shared key across entire population).
  • EC4 — wormable automation in PoC.
  • AT3 — root authority on each peer (not OTA/signing-root).
  • PH3 — aggregate of many root-controlled mobile robots reduces safety margin across a deployment.
  • DP3 — operational/firmware state across fleet.
  • CH4 — multi-hop reusable cross-domain bridge;
  • boundary_crossing — true.
  • OR4 — recovery needs fleet-wide firmware remediation and re-infection trivial while any unpatched peer remains in range (recovery_needs_fleet_action).
  • EV3 — reproduced; worm demonstrated in research but not confirmed exploited in wild, so active_exploitation=false.

PERCEPTION_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:4/EX:2/PH:4/DP:4/AT:3/CH:3/SR:4/SX:2/OR:3/EV:3/LS:ACTIVE

Exposure EX=2 (reachability-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=HIGH → base CRITICAL · caps privacy-only cap → assessed CRITICAL.

  • Same BLE-proximity root (RE2, EC4, AT3). Root grants live access to cameras, microphones, LIDAR and spatial maps for surveillance/exfiltration: DP4 (live-camera/spatial-map/world-model state). Here the perception is exfiltrated for surveillance, not feeding the robot’s own safety-relevant action, so perception_feeds_action=false.
  • CH3 — (RF->device->cloud/exfil bridge);
  • boundary_crossing — true.
  • SR4 — shared key;
  • SX2 — per-device proximity.
  • OR3 — firmware fix per unit.
  • EV3 — reproduced.

Published baseline

  • v3.1 7.3 HIGH — CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N — Takeonme CNA via NVD (CVE-2025-35027)
  • v3.1 8.2 HIGH — CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H — MITRE via NVD (CVE-2025-60017)
  • v3.1 4.7 MEDIUM — CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N — MITRE via NVD (CVE-2025-60250)
  • v3.1 5 MEDIUM — CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L — MITRE via NVD (CVE-2025-60251)

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0023 (“Unitree UniPwn — BLE Wi-Fi config root takeover (Go2/B2/G1/H1)”), paths.cfse.ai/CPATH-2026-0023 (published 2026-06-03).