Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other versions may be affected, such as the A1.
References
Link | Resource |
---|---|
https://www.mybotshop.de/Datasheet/Unitree_A1_User_Manual_v1.0.pdf | Product Third Party Advisory |
https://fccid.io/2A5PE-YUSHU001/Users-Manual/User-Manual-5810729 | Product Third Party Advisory |
https://twitter.com/d0tslash/status/1555326302462394370 | Third Party Advisory |
Information
Published : 2022-08-05 10:15
Updated : 2022-08-11 08:28
NVD link : CVE-2022-2675
Mitre link : CVE-2022-2675
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
unitree
- go_1_firmware
- go_1