← Registry

CPATH-2026-0026 · ROBOTICS HUMANOID

Unitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894)

Provisional. Candidate score (CFSE Consequence Paths 1.0-candidate); pending independent review. Treat as a structured second opinion, not a final rating.
Paths EMERGENCY Dominant consequence DEVICE_CONTROL_SAFETY Physical/safety · Evidence EV:4 (field-confirmed) · Liveness MITIGATED
CPATH IDCPATH-2026-0026
CVE(s)CVE-2025-2894
Device / classUnitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894) (ROBOTICS HUMANOID)
VendorUnitree
Dominant consequenceDEVICE_CONTROL_SAFETY (Physical/safety)
Paths verdictEMERGENCY (worst of 3 paths)
Published baseline
v3.1 6.6 MEDIUM CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H · Takeonme CNA via NVD
Baseline relationship▼ Paths higher
Consequence dimension(s)#1 #2 #8 (what these mean)
Scored2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional
Baseline confidencehigh

Consequence Paths

Paths Assessment

Physical/safety

DEVICE_CONTROL_SAFETY

EMERGENCY
Reachability RE:4
Complexity EC:3
Consequence DEVICE_CONTROL_SAFETY
Scale SR:4 / SX:4
Verdict EMERGENCY
Reachability 4
Complexity 3
Exposure 3
Physical / safety 4
Data / perception 3
Authority 3
Chainability 4
Reuse scale 4
Execution scale 4
Recovery 4
Evidence EV:4 · field-confirmed
Liveness MITIGATED
Vector CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:4/LS:MITIGATED

authority

FLEET_CONTROL_PLANE

EMERGENCY
Reachability RE:4
Complexity EC:3
Consequence FLEET_CONTROL_PLANE
Scale SR:4 / SX:4
Verdict EMERGENCY
Reachability 4
Complexity 3
Exposure 3
Physical / safety 4
Data / perception 3
Authority 4
Chainability 4
Reuse scale 4
Execution scale 4
Recovery 4
Evidence EV:4 · field-confirmed
Liveness MITIGATED
Vector CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:3/EX:3/PH:4/DP:3/AT:4/CH:4/SR:4/SX:4/OR:4/EV:4/LS:MITIGATED

perception

PERCEPTION_PRIVACY

CRITICAL
Reachability RE:4
Complexity EC:3
Consequence PERCEPTION_PRIVACY
Scale SR:4 / SX:4
Verdict CRITICAL
Reachability 4
Complexity 3
Exposure 3
Physical / safety 4
Data / perception 4
Authority 3
Chainability 3
Reuse scale 4
Execution scale 4
Recovery 4
Evidence EV:4 · field-confirmed
Liveness MITIGATED
Vector CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:4/EC:3/EX:3/PH:4/DP:4/AT:3/CH:3/SR:4/SX:4/OR:4/EV:4/LS:MITIGATED

Assessment

CFSE Consequence Paths assesses Unitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894) at EMERGENCY — the worst of 3 risk paths (safety, authority, perception). The dominant consequence is influence over a safety-relevant actuation.

Vulnerability

Unitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894). Reported attack vector: Network (outbound-initiated tunnel, bypasses NAT/firewall).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYEMERGENCY

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:4/LS:MITIGATED

Exposure EX=3 (execution complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.

FLEET_CONTROL_PLANEEMERGENCY

CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:3/EX:3/PH:4/DP:3/AT:4/CH:4/SR:4/SX:4/OR:4/EV:4/LS:MITIGATED

Exposure EX=3 (execution complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.

Robots auto-dial outbound to unitree.com CloudSail, bypassing NAT/firewall, so reachable from internet regardless of inbound filtering (RE:4). Execution is conceptually simple once the shared API key is held; the manufacturer inherently holds it and Makris/Finisterre demonstrated live control (EC:3 standard workflow, gated only by key possession). A single API key enumerates and controls EVERY registered robot (1,919 devices) — a hidden remote-control plane keyed on one shared trust anchor (AT:4, SR:4 shared key/backdoor, SX:4 fleet-scale remote/cloud). Crosses cloud/device/physical boundaries (CH:4, boundary_crossing). Recovery requires removing the hidden CloudSail functionality across the fleet plus egress filtering and firmware change (OR:4, recovery_needs_fleet_action). Field-confirmed via telemetry (EV:4). Not known exploited maliciously in the wild (active_exploitation:false). Liveness MITIGATED — service can be disabled and Go2+ changed architecture.

PERCEPTION_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:4/EC:3/EX:3/PH:4/DP:4/AT:3/CH:3/SR:4/SX:4/OR:4/EV:4/LS:MITIGATED

Exposure EX=3 (execution complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority, recall-class recovery · caps privacy-only cap → assessed CRITICAL.

Published baseline

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Score it yourself in the calculator Review this score
Cite this entry: CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0026 (“Unitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894)”), paths.cfse.ai/CPATH-2026-0026 (published 2026-06-03).