Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within restart_wifi_ap and restart_wifi_sta).
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Unitree多款产品 安全漏洞
Vulnerability Description
Unitree Go2等都是中国宇树(Unitree)公司的产品。Unitree Go2是一款机器狗。Unitree G1是一款人形机器人。Unitree H1是一款人形机器人。 Unitree多款产品存在安全漏洞,该漏洞源于hostapd_restart.sh中wifi_ssid或wifi_pass参数存在OS命令注入漏洞。以下产品及版本受到影响:Unitree Go2、G1、H1和B2 2025-09-20及之前版本。
CVSS Information
N/A
Vulnerability Type
N/A