← Registry

CPATH-2026-0025 · ROBOTICS HUMANOID

Unitree Go2 Android-app database tampering RCE (CVE-2026-27510)

Provisional. Candidate score (CFSE Consequence Paths 1.0-candidate); pending independent review. Treat as a structured second opinion, not a final rating.
Paths CRITICAL Dominant consequence PERCEPTION_PRIVACY perception · Evidence EV:2 (report-backed) · Liveness PATCH_AVAILABLE
CPATH IDCPATH-2026-0025
CVE(s)CVE-2026-27510
Device / classUnitree Go2 Android-app database tampering RCE (CVE-2026-27510) (ROBOTICS HUMANOID)
VendorUnitree
Dominant consequencePERCEPTION_PRIVACY (perception)
Paths verdictCRITICAL (worst of 2 paths)
Published baseline
v4.0 6.4 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X · VulnCheck via NVD
v3.1 9.6 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H · VulnCheck via NVD
v3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H · NVD
Baseline relationship◀▶ comparable
Consequence dimension(s)#2 #7 (what these mean)
Scored2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional
Baseline confidencehigh

Consequence Paths

Paths Assessment

Physical/safety

DEVICE_CONTROL_SAFETY

HIGH
Reachability RE:3
Complexity EC:2
Consequence DEVICE_CONTROL_SAFETY
Scale SR:3 / SX:1
Verdict HIGH
Reachability 3
Complexity 2
Exposure 2
Physical / safety 3
Data / perception 3
Authority 3
Chainability 3
Reuse scale 3
Execution scale 1
Recovery 3
Evidence EV:3 · reproduced / report-backed
Liveness PATCH_AVAILABLE
Vector CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:3/EC:2/EX:2/PH:3/DP:3/AT:3/CH:3/SR:3/SX:1/OR:3/EV:3/LS:PATCH_AVAILABLE

perception

PERCEPTION_PRIVACY

CRITICAL
Reachability RE:3
Complexity EC:2
Consequence PERCEPTION_PRIVACY
Scale SR:3 / SX:1
Verdict CRITICAL
Reachability 3
Complexity 2
Exposure 2
Physical / safety 3
Data / perception 4
Authority 3
Chainability 2
Reuse scale 3
Execution scale 1
Recovery 3
Evidence EV:2 · report-backed
Liveness PATCH_AVAILABLE
Vector CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:2/EX:2/PH:3/DP:4/AT:3/CH:2/SR:3/SX:1/OR:3/EV:2/LS:PATCH_AVAILABLE

Assessment

CFSE Consequence Paths assesses Unitree Go2 Android-app database tampering RCE (CVE-2026-27510) at CRITICAL — the worst of 2 risk paths (safety, perception). The dominant consequence is exposure of sensor or biometric data.

Vulnerability

Unitree Go2 Android-app database tampering RCE (CVE-2026-27510). Reported attack vector: Local (rooted Android device with app DB access).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYHIGH

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:3/EC:2/EX:2/PH:3/DP:3/AT:3/CH:3/SR:3/SX:1/OR:3/EV:3/LS:PATCH_AVAILABLE

Exposure EX=2 (execution complexity-bound) · bands PH=HIGH · DP=HIGH · AT=HIGH → base HIGH → assessed HIGH.

PERCEPTION_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:2/EX:2/PH:3/DP:4/AT:3/CH:2/SR:3/SX:1/OR:3/EV:2/LS:PATCH_AVAILABLE

Exposure EX=2 (execution complexity-bound) · bands PH=HIGH · DP=CRITICAL · AT=HIGH → base CRITICAL · caps privacy-only cap → assessed CRITICAL.

Published baseline

The published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.

Sources

Score it yourself in the calculator Review this score
Cite this entry: CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0025 (“Unitree Go2 Android-app database tampering RCE (CVE-2026-27510)”), paths.cfse.ai/CPATH-2026-0025 (published 2026-06-03).