CPATH-2026-0026 · Robotics / humanoid

Unitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894)

Two or more co-dominant consequence paths connect the public security record to a provisional EMERGENCY consequence band.

Candidate bandEMERGENCY
Co-dominant pathsDevice-control safety + Fleet control plane

These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

3 candidate paths · explicit source, inference, and assumption boundaries.

Safety · Co-dominant path

Device-control safety

Remote motion control of a walking quadruped can create a collision or bystander hazard, especially in security-sensitive deployments.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    The undocumented remote service is reachable through the vendor cloud path when the shared API authority is available.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    Crosses cloud-to-physical-actuation boundary.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Severe therapy or actuation consequence

    Remote motion control of a walking quadruped can create a collision or bystander hazard, especially in security-sensitive deployments.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Remote motion control of a walking quadruped can create a collision or bystander hazard, especially in security-sensitive deployments.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Removal requires firmware and service change fleet-wide (fleet-wide recovery is required).

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The undocumented remote service is reachable through the vendor cloud path when the shared API authority is available.

Source-backedNVD
Execution complexityEC 3
Reproducible exploit workflow

With the shared CloudSail key, the demonstrated service workflow provides repeatable remote shell and motion commands through the robot's outbound tunnel.

Source-backedNVD
ExposureEX 3
Execution effort limits exposure

The interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Remote motion control of a walking quadruped can create a collision or bystander hazard, especially in security-sensitive deployments.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Remote root exposes the robot's sensor, configuration, and operational state alongside its motion controls.

Model inference
AuthorityAT 3
Administrative or command authority

The service provides remote motion commands and SSH root on the onboard host; it does not expose a vendor firmware-signing key.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Crosses cloud-to-physical-actuation boundary.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same shared CloudSail credential and service workflow can be reused to send motion commands to registered robots.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

The shared service path can address registered robots over their outbound tunnels without placing an attacker beside each device.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Removal requires firmware and service change fleet-wide (fleet-wide recovery is required).

Operational assumption
Confidence and status
Evidence strengthEV 4
Field-confirmed evidence

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Mitigated
Vendor mitigation is recorded

The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. Systemic uplift

    The CRITICAL base band rises to EMERGENCY because the shared remote service and API key can reach many registered robots, and remediation must revoke that fleet-wide authority.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:4/LS:MITIGATEDRead the scoring method →

Systemic · Co-dominant path

Fleet control plane

One shared API key was reported to enumerate and control 1,919 registered robots through a hidden remote service.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    Robots auto-dial outbound to unitree.com CloudSail, bypassing NAT and firewall, so reachable from internet regardless of inbound filtering.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    Crosses cloud and device and physical boundaries.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Firmware or trust-root authority

    One shared API key was reported to enumerate and control 1,919 registered robots through a hidden remote service.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Fleet control plane

    One shared API key was reported to enumerate and control 1,919 registered robots through a hidden remote service.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Recovery requires removing the hidden CloudSail functionality across the fleet plus egress filtering and firmware change (fleet-wide recovery is required).

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

Robots auto-dial outbound to unitree.com CloudSail, bypassing NAT and firewall, so reachable from internet regardless of inbound filtering.

Source-backedNVD
Execution complexityEC 3
Reproducible exploit workflow

The manufacturer inherently holds it and Makris and Finisterre demonstrated live control (standard workflow, gated only by key possession).

Source-backedNVD
ExposureEX 3
Execution effort limits exposure

The interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Coordinated remote motion or shutdown across many mobile robots can reduce safety margins across the deployment; observed injury is not asserted.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The shared control plane exposes fleet inventory, robot status, sensor access, and command state across registered devices.

Model inference
AuthorityAT 4
Firmware or trust-root authority

One shared API key was reported to enumerate and control 1,919 registered robots through a hidden remote service.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Crosses cloud and device and physical boundaries.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

One shared API key and hidden service workflow apply across the registered robot population.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

The hidden cloud service can address registered robots through their outbound tunnels without per-device physical access.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Recovery requires removing the hidden CloudSail functionality across the fleet plus egress filtering and firmware change (fleet-wide recovery is required).

Operational assumption
Confidence and status
Evidence strengthEV 4
Field-confirmed evidence

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Mitigated
Vendor mitigation is recorded

The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. Systemic uplift

    The CRITICAL base band rises to EMERGENCY because one shared API key reaches the remote control plane of many registered robots and requires coordinated fleet remediation.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:3/EX:3/PH:4/DP:3/AT:4/CH:4/SR:4/SX:4/OR:4/EV:4/LS:MITIGATEDRead the scoring method →

Privacy · Supporting path

Perception privacy

The shared service can expose live camera feeds and sensor state from registered robots, enabling remote observation of their surroundings.

CRITICAL
  1. accessSource-backed

    Network-reachable without prior access

    The undocumented remote service is reachable through the vendor cloud path when the shared API authority is available.

    EvidenceNVD

  2. boundaryModel inference

    Reusable multi-stage bridge

    Crosses cloud and device and physical-observation boundary.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Safety-driving perception or intimate data

    The shared service can expose live camera feeds and sensor state from registered robots, enabling remote observation of their surroundings.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Perception privacy

    The shared service can expose live camera feeds and sensor state from registered robots, enabling remote observation of their surroundings.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Recovery requires fleet-wide service and firmware removal (fleet-wide recovery is required).

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The undocumented remote service is reachable through the vendor cloud path when the shared API authority is available.

Source-backedNVD
Execution complexityEC 3
Reproducible exploit workflow

Possession of the shared CloudSail key gives the demonstrated service access to live cameras and sensors through the existing outbound tunnel.

Source-backedNVD
ExposureEX 3
Execution effort limits exposure

The interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Surveillance itself is an information and privacy disruption, not direct actuation harm.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

The shared service can expose live camera feeds and sensor state from registered robots, enabling remote observation of their surroundings.

Model inference
AuthorityAT 3
Administrative or command authority

Sensor and camera access via service authority.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

Crosses cloud and device and physical-observation boundary.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

Shared single key gives fleet-wide remote camera access .

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

The same service credential can request sensor access from registered robots remotely rather than requiring per-robot physical proximity.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Recovery requires fleet-wide service and firmware removal (fleet-wide recovery is required).

Operational assumption
Confidence and status
Evidence strengthEV 4
Field-confirmed evidence

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Mitigated
Vendor mitigation is recorded

The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. The shared service can expose live camera feeds and sensor state from registered robots, enabling remote observation of their surroundings.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:4/EC:3/EX:3/PH:2/DP:4/AT:3/CH:3/SR:4/SX:4/OR:4/EV:4/LS:MITIGATEDRead the scoring method →

Triage implication

Verify the safety transition before acting on the band.

Triage beyond the first device: verify whether the reusable condition, propagation mechanism, and recovery dependency actually exist across the deployment.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 6.6 MEDIUMTakeonme CNA via NVD
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Unitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894) at EMERGENCY — the worst of 3 risk paths (safety, authority, perception). The dominant consequence is influence over a safety-relevant actuation.

Vulnerability

Unitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894). Reported attack vector: Network (outbound-initiated tunnel, bypasses NAT/firewall).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYEMERGENCY

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:4/LS:MITIGATED

Exposure EX=3 (execution complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.

  • Same internet-reachable outbound tunnel position (RE:4) and key-gated but reproducible execution (EC:3). Authority is full remote device control: motion/locomotion commands plus SSH root to the onboard Raspberry Pi host (AT:3 device/host control – not a signing-root/OTA-root so not AT:4). PH:4 because remote motion control of an autonomously walking ~12kg quadruped creates credible dangerous-actuation/bystander injury risk, amplified by deployments cited at prisons/police/military. Crosses cloud-to-physical-actuation boundary (CH:4, boundary_crossing). Same shared-key reuse and fleet-scale remote actuation (SR:4, SX:4). Removal requires firmware/service change fleet-wide (OR:4, recovery_needs_fleet_action). Field-confirmed (EV:4).
  • perception_feeds_action — false here because the actuation is direct operator command injection, not driven by a manipulated perception channel.

FLEET_CONTROL_PLANEEMERGENCY

CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:3/EX:3/PH:4/DP:3/AT:4/CH:4/SR:4/SX:4/OR:4/EV:4/LS:MITIGATED

Exposure EX=3 (execution complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.

Robots auto-dial outbound to unitree.com CloudSail, bypassing NAT/firewall, so reachable from internet regardless of inbound filtering (RE:4). Execution is conceptually simple once the shared API key is held; the manufacturer inherently holds it and Makris/Finisterre demonstrated live control (EC:3 standard workflow, gated only by key possession). A single API key enumerates and controls EVERY registered robot (1,919 devices) – a hidden remote-control plane keyed on one shared trust anchor (AT:4, SR:4 shared key/backdoor, SX:4 fleet-scale remote/cloud). Crosses cloud/device/physical boundaries (CH:4, boundary_crossing). Recovery requires removing the hidden CloudSail functionality across the fleet plus egress filtering and firmware change (OR:4, recovery_needs_fleet_action). Field-confirmed via telemetry (EV:4). Not known exploited maliciously in the wild (active_exploitation:false). Liveness MITIGATED – service can be disabled and Go2+ changed architecture.

PERCEPTION_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:4/EC:3/EX:3/PH:4/DP:4/AT:3/CH:3/SR:4/SX:4/OR:4/EV:4/LS:MITIGATED

Exposure EX=3 (execution complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority, recall-class recovery · caps privacy-only cap → assessed CRITICAL.

  • Same internet-reachable tunnel (RE:4) and key-gated reproducible access (EC:3). Holder can view live camera feeds and sensor data – ‘see through their eyes’ – across the fleet (DP:4 live-camera/spatial perception state; AT:3 sensor/camera access via service authority). Raised as an espionage/national-security surveillance risk by US lawmakers given academic/corporate networks (MIT, Princeton, CMU, Waterloo) among 1,919 connected devices. PH:2 – surveillance itself is an information/privacy disruption, not direct actuation harm. Shared single key gives fleet-wide remote camera access (SR:4, SX:4). Crosses cloud/device/physical-observation boundary (CH:3, boundary_crossing). Recovery requires fleet-wide service/firmware removal (OR:4, recovery_needs_fleet_action). Field-confirmed (EV:4).
  • perception_feeds_action — false: this path is passive exfiltration for surveillance, not a perception channel feeding the robot’s own action/navigation decisions.

Published baseline

  • v3.1 6.6 MEDIUM — CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H — Takeonme CNA via NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0026 (“Unitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894)”), paths.cfse.ai/CPATH-2026-0026 (published 2026-06-03).