CPATH-2026-0025 · Robotics / humanoid

Unitree Go2 Android-app database tampering RCE (CVE-2026-27510)

A dominant perception privacy path connects the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Dominant pathPerception privacy

This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Privacy · Dominant path

Perception privacy

Root execution exposes the robot’s live camera feed and spatial-sensor state, revealing people and places around the device.

CRITICAL
  1. accessSource-backed

    Reusable artifact or reachable service

    The attacker needs an owned rooted Android phone and ADB access to inject content through the companion app database.

    EvidenceNVD

  2. boundaryModel inference

    One cross-boundary bridge

    Enables further access but is not a reusable cross-domain authority bridge.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Safety-driving perception or intimate data

    Root execution exposes the robot’s live camera feed and spatial-sensor state, revealing people and places around the device.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Perception privacy

    Root execution exposes the robot’s live camera feed and spatial-sensor state, revealing people and places around the device.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Recovery requires removing the tampered database, restoring trusted app state, and checking the paired robot for unauthorized changes.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 3
Reusable artifact or reachable service

The attacker needs an owned rooted Android phone and ADB access to inject content through the companion app database.

Source-backedNVD
Execution complexityEC 2
Specialist multi-step technique

Reproducible-but-advanced gives root on the robot, which grants live camera and sensor access for exfiltration.

Source-backedNVD
ExposureEX 2
Execution effort limits exposure

The interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 1
Minor physical effect

Privacy exfiltration is at most a nuisance to physical safety on this path.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

Root execution exposes the robot’s live camera feed and spatial-sensor state, revealing people and places around the device.

Model inference
AuthorityAT 3
Administrative or command authority

Root execution authority enabling the read.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

Enables further access but is not a reusable cross-domain authority bridge.

Model inference
Reuse scaleSR 3
Portable product-class technique

Systemic no-validation root cause generalizes across units.

Operational assumption
Execution scaleSX 1
One device at a time

Each sensor-access attempt depends on a rooted operator phone and the local companion-app workflow; there is no automated peer propagation.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Recovery requires removing the tampered database, restoring trusted app state, and checking the paired robot for unauthorized changes.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Root execution exposes the robot’s live camera feed and spatial-sensor state, revealing people and places around the device.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:2/EX:2/PH:1/DP:4/AT:3/CH:2/SR:3/SX:1/OR:3/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Safety · Supporting path

Device-control safety

Tampered app database content can lead to root and motion control, enabling unsafe actuation that can endanger nearby people.

HIGH
  1. accessSource-backed

    Reusable artifact or reachable service

    The attacker needs an owned rooted Android phone and ADB access to extract, modify, and restore the companion app database.

    EvidenceNVD

  2. boundaryModel inference

    Reusable multi-stage bridge

    Crosses app to device and physical to safety boundaries but not a reusable cross-domain key bridge.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Credible safety consequence

    Tampered app database content can lead to root and motion control, enabling unsafe actuation that can endanger nearby people.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Tampered app database content can lead to root and motion control, enabling unsafe actuation that can endanger nearby people.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Real fix is robot-side validation of uploaded Python.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 3
Reusable artifact or reachable service

The attacker needs an owned rooted Android phone and ADB access to extract, modify, and restore the companion app database.

Source-backedNVD
Execution complexityEC 2
Specialist multi-step technique

The attacker needs a rooted Android device, must alter the companion-app database, and then relies on the operator to trigger the modified key binding.

Source-backedNVD
ExposureEX 2
Execution effort limits exposure

The interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 3
Credible safety consequence

Tampered app database content can lead to root and motion control, enabling unsafe actuation that can endanger nearby people.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Root execution can expose companion-app data, robot configuration, and operational state.

Model inference
AuthorityAT 3
Administrative or command authority

The altered binding reaches root command execution through the robot actuator manager, but it does not compromise a vendor signing key.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

Crosses app to device and physical to safety boundaries but not a reusable cross-domain key bridge.

Model inference
Reuse scaleSR 3
Portable product-class technique

The missing robot-side validation is shared across affected units, so the method is reusable even though it does not expose a universal secret.

Operational assumption
Execution scaleSX 1
One device at a time

Each attempt needs control of a rooted operator phone and the local companion-app workflow; it does not spread automatically between robots.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Real fix is robot-side validation of uploaded Python.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandHIGH
  2. No adjustment

    The HIGH base band remains final because no separate cap or systemic uplift applies. Tampered app database content can lead to root and motion control, enabling unsafe actuation that can endanger nearby people.

  3. Final candidate bandHIGH
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:3/EC:2/EX:2/PH:3/DP:3/AT:3/CH:3/SR:3/SX:1/OR:3/EV:3/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the privacy transition before acting on the band.

Protect the outward data or sensor boundary and verify what sensitive behavior can be reconstructed, not only what raw fields are exposed.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipDifferent consequence axis
Baseline confidencehigh
Scored2026-06-03
v4.0 · 6.4 MEDIUMVulnCheck via NVD
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
v3.1 · 9.6 CRITICALVulnCheck via NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
v3.1 · 8.8 HIGHNVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Unitree Go2 Android-app database tampering RCE (CVE-2026-27510) at CRITICAL — the worst of 2 risk paths (safety, perception). The dominant consequence is exposure of sensor or biometric data.

Vulnerability

Unitree Go2 Android-app database tampering RCE (CVE-2026-27510). Reported attack vector: Local (rooted Android device with app DB access).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYHIGH

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:3/EC:2/EX:2/PH:3/DP:3/AT:3/CH:3/SR:3/SX:1/OR:3/EV:3/LS:PATCH_AVAILABLE

Exposure EX=2 (execution complexity-bound) · bands PH=HIGH · DP=HIGH · AT=HIGH → base HIGH → assessed HIGH.

  • Attacker uses their own rooted Android device + ADB to extract, tamper, and restore the app’s SQLite DB (own artifact / privileged access to a controlling phone, no victim hardware touched) -> RE:3. EC:2 advanced-but-reproducible: needs rooted device, DB manipulation, and the operator to trigger the keybinding; researcher demonstrated full chain. AT:3 root-level command execution on the robot via the actuator_manager path (device command/firmware-level authority, not a signing/OTA root, so not 4). PH:3 root + motion control yields direct unsafe actuation and bystander safety risk; credible but not demonstrated injury/life-support so 3 not 4. DP:3 root grants sensor/firmware/op-state access. CH:3 crosses app -> device/physical -> safety boundaries (boundary_crossing true) but not a reusable cross-domain key bridge. SR:3 same systemic root cause (no robot-side content validation) generalizes across affected units, but it is a shared design flaw not a portable key/default cred (not 4). SX:1 per-device: each exploit needs a rooted operator phone and physical/privileged access, not wormable. OR:3 real fix is robot-side validation of uploaded Python; app DB hardening insufficient; cleanup needs removing tampered dog_programme entries, but no fleet recall/signing-root rotation so not 4. EV:3 reproduced.
  • perception_feeds_action — false: this path is actuation, not exposed perception driving action.
  • active_exploitation — false (alternate-path research disclosure).

PERCEPTION_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:2/EX:2/PH:3/DP:4/AT:3/CH:2/SR:3/SX:1/OR:3/EV:2/LS:PATCH_AVAILABLE

Exposure EX=2 (execution complexity-bound) · bands PH=HIGH · DP=CRITICAL · AT=HIGH → base CRITICAL · caps privacy-only cap → assessed CRITICAL.

  • Same access and injection chain (RE:3 own rooted phone / app DB, EC:2 reproducible-but-advanced) gives root on the robot, which grants live camera and sensor access for exfiltration. DP:4 live-camera / spatial sensor state. AT:3 root execution authority enabling the read. PH:1 privacy exfiltration is at most a nuisance to physical safety on this path. CH:2 enables further access but is not a reusable cross-domain authority bridge;
  • boundary_crossing — true (device -> app/exfil). SR:3 systemic no-validation root cause generalizes across units; not a portable key. SX:1 per-device, needs rooted operator phone each time, not wormable. OR:3 same robot-side validation fix and entry cleanup, no fleet rotation. EV:2 report-backed: exfil is described as a capability of root but the primary demonstrated impact was code execution, not the camera exfil itself.
  • perception_feeds_action — false: the exposed perception is exfiltrated data, not feeding the robot’s own physical/navigation action on this path.
  • active_exploitation — false.

Published baseline

  • v4.0 6.4 MEDIUM — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X — VulnCheck via NVD
  • v3.1 9.6 CRITICAL — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H — VulnCheck via NVD
  • v3.1 8.8 HIGH — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H — NVD

The published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0025 (“Unitree Go2 Android-app database tampering RCE (CVE-2026-27510)”), paths.cfse.ai/CPATH-2026-0025 (published 2026-06-03).