Remote Code Execution Vulnerabilities in Unitree Go2 Robot
Severity: High (Score: 71.1)
Sources: Boschko.Ca, Dbugs.Ptsecurity
Summary
Two critical vulnerabilities, CVE-2026-27509 and CVE-2026-27510, were identified in the Unitree Go2 robot. CVE-2026-27509 allows unauthenticated remote code execution via DDS, while CVE-2026-27510 involves mobile database tampering leading to remote code execution. Both vulnerabilities were published on 2026-02-26.
Key Entities
- Zero-day Exploit (attack_type)
- CVE-2026-27509 (cve)
- CVE-2026-27510 (cve)