CVE-2025-60017: Unitree b2

High severity, CVSS 8.2. EPSS: 1.1% chance of exploitation in the next 30 days.

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within restart_wifi_ap and restart_wifi_sta).

Affected products

  • Unitree b2: up to and including 2025-09-20
  • Unitree g1: up to and including 2025-09-20
  • Unitree GO2: up to and including 2025-09-20
  • Unitree h1: up to and including 2025-09-20

Published 2025-09-26. Last modified 2026-06-17.