CVE-2026-1442 Details
Description
Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, and then trusted by a Unitree product, such as the Unitree Go2 and other models. This issue appears to affect all of Unitree’s current offerings as of February 26, 2026, and so should be considered a vulnerability in both the firmware generation and extraction processes. At the time of this release, there is no publicly-documented mechanism to subvert the update process and insert poisoned firmware packages without the equipment owner’s knowledge.
A vulnerability exists in Unitree robotics products, including the Go2 model, due to a flaw in the firmware update encryption process. The encryption algorithm, TEA, is compromised by hard-coded key material available to attackers, allowing unauthorized users to alter firmware updates. This issue affects all current Unitree offerings as of February 26, 2026, and represents a vulnerability in both firmware generation and extraction processes. At present, there is no documented method to covertly inject modified firmware into the update process.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 27, 2026CNA
Assessed Jan 1, 1References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Bin4ry/UniTEABag | [email protected] | ExploitThird Party Advisory |
| https://www.linkedin.com/posts/kevin-finisterre-6431069a_in-case-you-want-to-teabag-unitree-robotics-activity-7432984361014091776-zB4D | [email protected] | Third Party Advisory |
| https://x.com/bin4rydigit/status/2027197985625420242 | [email protected] | Third Party Advisory |
| http://takeonme.org/gcves/GCVE-1337-2025-00000000000000000000000000000000000000000000000001111111111110101111111111000000000000000000000000000000000000000000000000000000101 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| unitree go2 edu plus firmware | All versions |
CPE
Remediation
| |
| unitree go2 edu plus | All versions |
CPE
Remediation
| |
| unitree go1 pro firmware | All versions |
CPE
Remediation
| |
| unitree go1 pro | All versions |
CPE
Remediation
| |
| unitree go1 air firmware | All versions |
CPE
Remediation
| |
| unitree go1 air | All versions |
CPE
Remediation
| |
| unitree go2 x firmware | All versions |
CPE
Remediation
| |
| unitree go2 x | All versions |
CPE
Remediation
| |
| unitree go2 pro firmware | All versions |
CPE
Remediation
| |
| unitree go2 pro | All versions |
CPE
Remediation
| |
| unitree go2 air firmware | All versions |
CPE
Remediation
| |
| unitree go2 air | All versions |
CPE
Remediation
| |
| unitree go2 edu standard firmware | All versions |
CPE
Remediation
| |
| unitree go2 edu standard | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 11, 2026 | Initial Analysis | [email protected] |
| Feb 27, 2026 | New CVE Received | [email protected] |