Causal model
What has to happen for this consequence to hold?
3 candidate paths · explicit source, inference, and assumption boundaries.
Safety · Co-dominant path
Device-control safety
Remote motion control of a walking quadruped can create a collision or bystander hazard, especially in security-sensitive deployments.
Network-reachable without prior access
The undocumented remote service is reachable through the vendor cloud path when the shared API authority is available.
EvidenceNVD
Cross-domain authority chain
Crosses cloud-to-physical-actuation boundary.
EvidenceNo direct citation — inspect the declared inference or assumption.
Severe therapy or actuation consequence
Remote motion control of a walking quadruped can create a collision or bystander hazard, especially in security-sensitive deployments.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
Remote motion control of a walking quadruped can create a collision or bystander hazard, especially in security-sensitive deployments.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Removal requires firmware and service change fleet-wide (fleet-wide recovery is required).
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
The undocumented remote service is reachable through the vendor cloud path when the shared API authority is available.
- Execution complexity
EC 3 - Reproducible exploit workflow
With the shared CloudSail key, the demonstrated service workflow provides repeatable remote shell and motion commands through the robot's outbound tunnel.
- Exposure
EX 3 - Execution effort limits exposure
The interface is broadly reachable, but the required technique keeps practical exposure below that reach.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Remote motion control of a walking quadruped can create a collision or bystander hazard, especially in security-sensitive deployments.
- Data / perception
DP 3 - Sensitive device or personal data
Remote root exposes the robot's sensor, configuration, and operational state alongside its motion controls.
- Authority
AT 3 - Administrative or command authority
The service provides remote motion commands and SSH root on the onboard host; it does not expose a vendor firmware-signing key.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
Crosses cloud-to-physical-actuation boundary.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same shared CloudSail credential and service workflow can be reused to send motion commands to registered robots.
- Execution scale
SX 4 - Remote fleet-scale execution
The shared service path can address registered robots over their outbound tunnels without placing an attacker beside each device.
- Recovery burden
OR 4 - Fleet action or replacement
Removal requires firmware and service change fleet-wide (fleet-wide recovery is required).
Confidence and status
- Evidence strength
EV 4 - Field-confirmed evidence
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Mitigated - Vendor mitigation is recorded
The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.
Decision trail
How the final band follows
- Base bandCRITICAL
- Systemic uplift
The CRITICAL base band rises to EMERGENCY because the shared remote service and API key can reach many registered robots, and remediation must revoke that fleet-wide authority.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:4/LS:MITIGATEDRead the scoring method →Systemic · Co-dominant path
Fleet control plane
One shared API key was reported to enumerate and control 1,919 registered robots through a hidden remote service.
Network-reachable without prior access
Robots auto-dial outbound to unitree.com CloudSail, bypassing NAT and firewall, so reachable from internet regardless of inbound filtering.
EvidenceNVD
Cross-domain authority chain
Crosses cloud and device and physical boundaries.
EvidenceNo direct citation — inspect the declared inference or assumption.
Firmware or trust-root authority
One shared API key was reported to enumerate and control 1,919 registered robots through a hidden remote service.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet control plane
One shared API key was reported to enumerate and control 1,919 registered robots through a hidden remote service.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Recovery requires removing the hidden CloudSail functionality across the fleet plus egress filtering and firmware change (fleet-wide recovery is required).
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
Robots auto-dial outbound to unitree.com CloudSail, bypassing NAT and firewall, so reachable from internet regardless of inbound filtering.
- Execution complexity
EC 3 - Reproducible exploit workflow
The manufacturer inherently holds it and Makris and Finisterre demonstrated live control (standard workflow, gated only by key possession).
- Exposure
EX 3 - Execution effort limits exposure
The interface is broadly reachable, but the required technique keeps practical exposure below that reach.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Coordinated remote motion or shutdown across many mobile robots can reduce safety margins across the deployment; observed injury is not asserted.
- Data / perception
DP 3 - Sensitive device or personal data
The shared control plane exposes fleet inventory, robot status, sensor access, and command state across registered devices.
- Authority
AT 4 - Firmware or trust-root authority
One shared API key was reported to enumerate and control 1,919 registered robots through a hidden remote service.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
Crosses cloud and device and physical boundaries.
- Reuse scale
SR 4 - Shared fleet-wide primitive
One shared API key and hidden service workflow apply across the registered robot population.
- Execution scale
SX 4 - Remote fleet-scale execution
The hidden cloud service can address registered robots through their outbound tunnels without per-device physical access.
- Recovery burden
OR 4 - Fleet action or replacement
Recovery requires removing the hidden CloudSail functionality across the fleet plus egress filtering and firmware change (fleet-wide recovery is required).
Confidence and status
- Evidence strength
EV 4 - Field-confirmed evidence
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Mitigated - Vendor mitigation is recorded
The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.
Decision trail
How the final band follows
- Base bandCRITICAL
- Systemic uplift
The CRITICAL base band rises to EMERGENCY because one shared API key reaches the remote control plane of many registered robots and requires coordinated fleet remediation.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:3/EX:3/PH:4/DP:3/AT:4/CH:4/SR:4/SX:4/OR:4/EV:4/LS:MITIGATEDRead the scoring method →Privacy · Supporting path
Perception privacy
The shared service can expose live camera feeds and sensor state from registered robots, enabling remote observation of their surroundings.
Network-reachable without prior access
The undocumented remote service is reachable through the vendor cloud path when the shared API authority is available.
EvidenceNVD
Reusable multi-stage bridge
Crosses cloud and device and physical-observation boundary.
EvidenceNo direct citation — inspect the declared inference or assumption.
Safety-driving perception or intimate data
The shared service can expose live camera feeds and sensor state from registered robots, enabling remote observation of their surroundings.
EvidenceNo direct citation — inspect the declared inference or assumption.
Perception privacy
The shared service can expose live camera feeds and sensor state from registered robots, enabling remote observation of their surroundings.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Recovery requires fleet-wide service and firmware removal (fleet-wide recovery is required).
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
The undocumented remote service is reachable through the vendor cloud path when the shared API authority is available.
- Execution complexity
EC 3 - Reproducible exploit workflow
Possession of the shared CloudSail key gives the demonstrated service access to live cameras and sensors through the existing outbound tunnel.
- Exposure
EX 3 - Execution effort limits exposure
The interface is broadly reachable, but the required technique keeps practical exposure below that reach.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Surveillance itself is an information and privacy disruption, not direct actuation harm.
- Data / perception
DP 4 - Safety-driving perception or intimate data
The shared service can expose live camera feeds and sensor state from registered robots, enabling remote observation of their surroundings.
- Authority
AT 3 - Administrative or command authority
Sensor and camera access via service authority.
Scale and recovery
- Chainability
CH 3 - Reusable multi-stage bridge
Crosses cloud and device and physical-observation boundary.
- Reuse scale
SR 4 - Shared fleet-wide primitive
Shared single key gives fleet-wide remote camera access .
- Execution scale
SX 4 - Remote fleet-scale execution
The same service credential can request sensor access from registered robots remotely rather than requiring per-robot physical proximity.
- Recovery burden
OR 4 - Fleet action or replacement
Recovery requires fleet-wide service and firmware removal (fleet-wide recovery is required).
Confidence and status
- Evidence strength
EV 4 - Field-confirmed evidence
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Mitigated - Vendor mitigation is recorded
The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. The shared service can expose live camera feeds and sensor state from registered robots, enabling remote observation of their surroundings.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:4/EC:3/EX:3/PH:2/DP:4/AT:3/CH:3/SR:4/SX:4/OR:4/EV:4/LS:MITIGATEDRead the scoring method →Triage implication
Verify the safety transition before acting on the band.
Triage beyond the first device: verify whether the reusable condition, propagation mechanism, and recovery dependency actually exist across the deployment.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HCVE recordsCVE-2025-2894
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Unitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894) at EMERGENCY — the worst of 3 risk paths (safety, authority, perception). The dominant consequence is influence over a safety-relevant actuation.
Vulnerability
Unitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894). Reported attack vector: Network (outbound-initiated tunnel, bypasses NAT/firewall).
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → EMERGENCY
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:4/LS:MITIGATED
Exposure EX=3 (execution complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.
- Same internet-reachable outbound tunnel position (RE:4) and key-gated but reproducible execution (EC:3). Authority is full remote device control: motion/locomotion commands plus SSH root to the onboard Raspberry Pi host (AT:3 device/host control – not a signing-root/OTA-root so not AT:4). PH:4 because remote motion control of an autonomously walking ~12kg quadruped creates credible dangerous-actuation/bystander injury risk, amplified by deployments cited at prisons/police/military. Crosses cloud-to-physical-actuation boundary (CH:4, boundary_crossing). Same shared-key reuse and fleet-scale remote actuation (SR:4, SX:4). Removal requires firmware/service change fleet-wide (OR:4, recovery_needs_fleet_action). Field-confirmed (EV:4).
- perception_feeds_action — false here because the actuation is direct operator command injection, not driven by a manipulated perception channel.
FLEET_CONTROL_PLANE → EMERGENCY
CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:3/EX:3/PH:4/DP:3/AT:4/CH:4/SR:4/SX:4/OR:4/EV:4/LS:MITIGATED
Exposure EX=3 (execution complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.
Robots auto-dial outbound to unitree.com CloudSail, bypassing NAT/firewall, so reachable from internet regardless of inbound filtering (RE:4). Execution is conceptually simple once the shared API key is held; the manufacturer inherently holds it and Makris/Finisterre demonstrated live control (EC:3 standard workflow, gated only by key possession). A single API key enumerates and controls EVERY registered robot (1,919 devices) – a hidden remote-control plane keyed on one shared trust anchor (AT:4, SR:4 shared key/backdoor, SX:4 fleet-scale remote/cloud). Crosses cloud/device/physical boundaries (CH:4, boundary_crossing). Recovery requires removing the hidden CloudSail functionality across the fleet plus egress filtering and firmware change (OR:4, recovery_needs_fleet_action). Field-confirmed via telemetry (EV:4). Not known exploited maliciously in the wild (active_exploitation:false). Liveness MITIGATED – service can be disabled and Go2+ changed architecture.
PERCEPTION_PRIVACY → CRITICAL
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:4/EC:3/EX:3/PH:4/DP:4/AT:3/CH:3/SR:4/SX:4/OR:4/EV:4/LS:MITIGATED
Exposure EX=3 (execution complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority, recall-class recovery · caps privacy-only cap → assessed CRITICAL.
- Same internet-reachable tunnel (RE:4) and key-gated reproducible access (EC:3). Holder can view live camera feeds and sensor data – ‘see through their eyes’ – across the fleet (DP:4 live-camera/spatial perception state; AT:3 sensor/camera access via service authority). Raised as an espionage/national-security surveillance risk by US lawmakers given academic/corporate networks (MIT, Princeton, CMU, Waterloo) among 1,919 connected devices. PH:2 – surveillance itself is an information/privacy disruption, not direct actuation harm. Shared single key gives fleet-wide remote camera access (SR:4, SX:4). Crosses cloud/device/physical-observation boundary (CH:3, boundary_crossing). Recovery requires fleet-wide service/firmware removal (OR:4, recovery_needs_fleet_action). Field-confirmed (EV:4).
- perception_feeds_action — false: this path is passive exfiltration for surveillance, not a perception channel feeding the robot’s own action/navigation decisions.
Published baseline
- v3.1 6.6 MEDIUM —
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H— Takeonme CNA via NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0026 (“Unitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894)”), paths.cfse.ai/CPATH-2026-0026 (published 2026-06-03).