Physical/safety
DEVICE_CONTROL_SAFETY
Vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:3/EC:2/EX:2/PH:3/DP:3/AT:3/CH:3/SR:3/SX:1/OR:3/EV:3/LS:PATCH_AVAILABLE CPATH-2026-0025 · ROBOTICS HUMANOID
PERCEPTION_PRIVACY perception · Evidence EV:2 (report-backed) · Liveness PATCH_AVAILABLE | CPATH ID | CPATH-2026-0025 |
| CVE(s) | CVE-2026-27510 |
| Device / class | Unitree Go2 Android-app database tampering RCE (CVE-2026-27510) (ROBOTICS HUMANOID) |
| Vendor | Unitree |
| Dominant consequence | PERCEPTION_PRIVACY (perception) |
| Paths verdict | CRITICAL (worst of 2 paths) |
| Published baseline | v4.0 6.4 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X · VulnCheck via NVDv3.1 9.6 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H · VulnCheck via NVDv3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H · NVD |
| Baseline relationship | ◀▶ comparable |
| Consequence dimension(s) | #2 #7 (what these mean) |
| Scored | 2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional |
| Baseline confidence | high |
Consequence Paths
Physical/safety
DEVICE_CONTROL_SAFETYCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:3/EC:2/EX:2/PH:3/DP:3/AT:3/CH:3/SR:3/SX:1/OR:3/EV:3/LS:PATCH_AVAILABLE perception
PERCEPTION_PRIVACYCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:2/EX:2/PH:3/DP:4/AT:3/CH:2/SR:3/SX:1/OR:3/EV:2/LS:PATCH_AVAILABLE CFSE Consequence Paths assesses Unitree Go2 Android-app database tampering RCE (CVE-2026-27510) at CRITICAL — the worst of 2 risk paths (safety, perception). The dominant consequence is exposure of sensor or biometric data.
Unitree Go2 Android-app database tampering RCE (CVE-2026-27510). Reported attack vector: Local (rooted Android device with app DB access).
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → HIGHCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:3/EC:2/EX:2/PH:3/DP:3/AT:3/CH:3/SR:3/SX:1/OR:3/EV:3/LS:PATCH_AVAILABLE
Exposure EX=2 (execution complexity-bound) · bands PH=HIGH · DP=HIGH · AT=HIGH → base HIGH → assessed HIGH.
PERCEPTION_PRIVACY → CRITICALCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:2/EX:2/PH:3/DP:4/AT:3/CH:2/SR:3/SX:1/OR:3/EV:2/LS:PATCH_AVAILABLE
Exposure EX=2 (execution complexity-bound) · bands PH=HIGH · DP=CRITICAL · AT=HIGH → base CRITICAL · caps privacy-only cap → assessed CRITICAL.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X — VulnCheck via NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H — VulnCheck via NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H — NVDThe published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.
CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0025 (“Unitree Go2 Android-app database tampering RCE (CVE-2026-27510)”), paths.cfse.ai/CPATH-2026-0025 (published 2026-06-03).