Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Privacy · Dominant path
Perception privacy
Root execution exposes the robot’s live camera feed and spatial-sensor state, revealing people and places around the device.
Reusable artifact or reachable service
The attacker needs an owned rooted Android phone and ADB access to inject content through the companion app database.
EvidenceNVD
One cross-boundary bridge
Enables further access but is not a reusable cross-domain authority bridge.
EvidenceNo direct citation — inspect the declared inference or assumption.
Safety-driving perception or intimate data
Root execution exposes the robot’s live camera feed and spatial-sensor state, revealing people and places around the device.
EvidenceNo direct citation — inspect the declared inference or assumption.
Perception privacy
Root execution exposes the robot’s live camera feed and spatial-sensor state, revealing people and places around the device.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Recovery requires removing the tampered database, restoring trusted app state, and checking the paired robot for unauthorized changes.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 3 - Reusable artifact or reachable service
The attacker needs an owned rooted Android phone and ADB access to inject content through the companion app database.
- Execution complexity
EC 2 - Specialist multi-step technique
Reproducible-but-advanced gives root on the robot, which grants live camera and sensor access for exfiltration.
- Exposure
EX 2 - Execution effort limits exposure
The interface is broadly reachable, but the required technique keeps practical exposure below that reach.
Consequence
- Physical / safety
PH 1 - Minor physical effect
Privacy exfiltration is at most a nuisance to physical safety on this path.
- Data / perception
DP 4 - Safety-driving perception or intimate data
Root execution exposes the robot’s live camera feed and spatial-sensor state, revealing people and places around the device.
- Authority
AT 3 - Administrative or command authority
Root execution authority enabling the read.
Scale and recovery
- Chainability
CH 2 - One cross-boundary bridge
Enables further access but is not a reusable cross-domain authority bridge.
- Reuse scale
SR 3 - Portable product-class technique
Systemic no-validation root cause generalizes across units.
- Execution scale
SX 1 - One device at a time
Each sensor-access attempt depends on a rooted operator phone and the local companion-app workflow; there is no automated peer propagation.
- Recovery burden
OR 3 - Coordinated operational recovery
Recovery requires removing the tampered database, restoring trusted app state, and checking the paired robot for unauthorized changes.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Root execution exposes the robot’s live camera feed and spatial-sensor state, revealing people and places around the device.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:2/EX:2/PH:1/DP:4/AT:3/CH:2/SR:3/SX:1/OR:3/EV:2/LS:PATCH_AVAILABLERead the scoring method →Safety · Supporting path
Device-control safety
Tampered app database content can lead to root and motion control, enabling unsafe actuation that can endanger nearby people.
Reusable artifact or reachable service
The attacker needs an owned rooted Android phone and ADB access to extract, modify, and restore the companion app database.
EvidenceNVD
Reusable multi-stage bridge
Crosses app to device and physical to safety boundaries but not a reusable cross-domain key bridge.
EvidenceNo direct citation — inspect the declared inference or assumption.
Credible safety consequence
Tampered app database content can lead to root and motion control, enabling unsafe actuation that can endanger nearby people.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
Tampered app database content can lead to root and motion control, enabling unsafe actuation that can endanger nearby people.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Real fix is robot-side validation of uploaded Python.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 3 - Reusable artifact or reachable service
The attacker needs an owned rooted Android phone and ADB access to extract, modify, and restore the companion app database.
- Execution complexity
EC 2 - Specialist multi-step technique
The attacker needs a rooted Android device, must alter the companion-app database, and then relies on the operator to trigger the modified key binding.
- Exposure
EX 2 - Execution effort limits exposure
The interface is broadly reachable, but the required technique keeps practical exposure below that reach.
Consequence
- Physical / safety
PH 3 - Credible safety consequence
Tampered app database content can lead to root and motion control, enabling unsafe actuation that can endanger nearby people.
- Data / perception
DP 3 - Sensitive device or personal data
Root execution can expose companion-app data, robot configuration, and operational state.
- Authority
AT 3 - Administrative or command authority
The altered binding reaches root command execution through the robot actuator manager, but it does not compromise a vendor signing key.
Scale and recovery
- Chainability
CH 3 - Reusable multi-stage bridge
Crosses app to device and physical to safety boundaries but not a reusable cross-domain key bridge.
- Reuse scale
SR 3 - Portable product-class technique
The missing robot-side validation is shared across affected units, so the method is reusable even though it does not expose a universal secret.
- Execution scale
SX 1 - One device at a time
Each attempt needs control of a rooted operator phone and the local companion-app workflow; it does not spread automatically between robots.
- Recovery burden
OR 3 - Coordinated operational recovery
Real fix is robot-side validation of uploaded Python.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandHIGH
- No adjustment
The HIGH base band remains final because no separate cap or systemic uplift applies. Tampered app database content can lead to root and motion control, enabling unsafe actuation that can endanger nearby people.
- Final candidate bandHIGH
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:3/EC:2/EX:2/PH:3/DP:3/AT:3/CH:3/SR:3/SX:1/OR:3/EV:3/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the privacy transition before acting on the band.
Protect the outward data or sensor boundary and verify what sensitive behavior can be reconstructed, not only what raw fields are exposed.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVE recordsCVE-2026-27510
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Unitree Go2 Android-app database tampering RCE (CVE-2026-27510) at CRITICAL — the worst of 2 risk paths (safety, perception). The dominant consequence is exposure of sensor or biometric data.
Vulnerability
Unitree Go2 Android-app database tampering RCE (CVE-2026-27510). Reported attack vector: Local (rooted Android device with app DB access).
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → HIGH
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:3/EC:2/EX:2/PH:3/DP:3/AT:3/CH:3/SR:3/SX:1/OR:3/EV:3/LS:PATCH_AVAILABLE
Exposure EX=2 (execution complexity-bound) · bands PH=HIGH · DP=HIGH · AT=HIGH → base HIGH → assessed HIGH.
- Attacker uses their own rooted Android device + ADB to extract, tamper, and restore the app’s SQLite DB (own artifact / privileged access to a controlling phone, no victim hardware touched) -> RE:3. EC:2 advanced-but-reproducible: needs rooted device, DB manipulation, and the operator to trigger the keybinding; researcher demonstrated full chain. AT:3 root-level command execution on the robot via the actuator_manager path (device command/firmware-level authority, not a signing/OTA root, so not 4). PH:3 root + motion control yields direct unsafe actuation and bystander safety risk; credible but not demonstrated injury/life-support so 3 not 4. DP:3 root grants sensor/firmware/op-state access. CH:3 crosses app -> device/physical -> safety boundaries (boundary_crossing true) but not a reusable cross-domain key bridge. SR:3 same systemic root cause (no robot-side content validation) generalizes across affected units, but it is a shared design flaw not a portable key/default cred (not 4). SX:1 per-device: each exploit needs a rooted operator phone and physical/privileged access, not wormable. OR:3 real fix is robot-side validation of uploaded Python; app DB hardening insufficient; cleanup needs removing tampered dog_programme entries, but no fleet recall/signing-root rotation so not 4. EV:3 reproduced.
- perception_feeds_action — false: this path is actuation, not exposed perception driving action.
- active_exploitation — false (alternate-path research disclosure).
PERCEPTION_PRIVACY → CRITICAL
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:2/EX:2/PH:3/DP:4/AT:3/CH:2/SR:3/SX:1/OR:3/EV:2/LS:PATCH_AVAILABLE
Exposure EX=2 (execution complexity-bound) · bands PH=HIGH · DP=CRITICAL · AT=HIGH → base CRITICAL · caps privacy-only cap → assessed CRITICAL.
- Same access and injection chain (RE:3 own rooted phone / app DB, EC:2 reproducible-but-advanced) gives root on the robot, which grants live camera and sensor access for exfiltration. DP:4 live-camera / spatial sensor state. AT:3 root execution authority enabling the read. PH:1 privacy exfiltration is at most a nuisance to physical safety on this path. CH:2 enables further access but is not a reusable cross-domain authority bridge;
- boundary_crossing — true (device -> app/exfil). SR:3 systemic no-validation root cause generalizes across units; not a portable key. SX:1 per-device, needs rooted operator phone each time, not wormable. OR:3 same robot-side validation fix and entry cleanup, no fleet rotation. EV:2 report-backed: exfil is described as a capability of root but the primary demonstrated impact was code execution, not the camera exfil itself.
- perception_feeds_action — false: the exposed perception is exfiltrated data, not feeding the robot’s own physical/navigation action on this path.
- active_exploitation — false.
Published baseline
- v4.0 6.4 MEDIUM —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X— VulnCheck via NVD - v3.1 9.6 CRITICAL —
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H— VulnCheck via NVD - v3.1 8.8 HIGH —
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H— NVD
The published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0025 (“Unitree Go2 Android-app database tampering RCE (CVE-2026-27510)”), paths.cfse.ai/CPATH-2026-0025 (published 2026-06-03).