PT-2026-22178 · Eclipse+1 · Eclipse Cyclonedds+1
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Unitree Go2 versions V1.1.7 through V1.1.9
Unitree Go2 version V1.1.11 (EDU)
Description
Lack of DDS authentication and authorization for the Eclipse CycloneDDS topic 'rt/api/programming actuator/request' handled by
actuator manager.py allows a network-adjacent, unauthenticated attacker to join DDS domain 0. By publishing a crafted message using the api id variable set to 1002, the attacker can send arbitrary Python code. The robot writes this code to the disk at /unitree/etc/programming/ and binds it to a physical controller keybinding. When the keybinding is triggered, the code executes with root privileges, and the binding remains active after reboots.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eclipse Cyclonedds
Unitree Go2