← GrokBot Source Archive

LC-3 · Consumer Risk Bulletins

Kinematic Risk Consumer Bulletin

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-3/monthly-2020-2026/2025/KRCB-2025-09.md
Imported-content SHA-256
e3adf5746b81021e2d521ac79b329791bf23a30c309f5a001e458b5ad7f3af4b
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# Kinematic Risk Consumer Bulletin

**LRRK Watch / Open-Source Intelligence** — Consumer kinematic electronics. Monthly filing.

**Issue type.** Monthly KRCB (retrospective). LC-3 (Consumer). Not the weekday 24–48h poll.

| Field | Value |
| --- | --- |
| Collection cutoff | 30 September 2025 |
| Window | 1–30 September 2025 |
| Written | 19 August 2026 (retrospective reconstruction) |
| Data label | Open-source intelligence // LRRK analytic product // retrospective monthly filing |
| Handling | Public-source material. Image rights require separate verification before publication. |
| Scope | Consumer kinematic electronics only (home, yard, companion, educational). |
| Classes in frame | Robot vacuums / mop combos · robotic lawn mowers · window-cleaning robots · pool-cleaning robots · robot pets / companion animals · social / desk companions · educational / programmable kits · robotic litter boxes · security / home patrol robots · consumer robotic arms · elder-care / assistive companions · kitchen / food-prep robots · toy / entertainment robots · niche outdoor / garden robots · emerging general-purpose or humanoid home robots |
| Spine | Reputable channels for injury, death, incidents, and safety recalls (CPSC, Health Canada, EU Safety Gate, UK OPSS, manufacturer recall pages, named newsrooms, dockets). |
| Color | Message boards, consumer forums, and Reddit — annotated context only. Never Fact without a reputable primary. |

## Executive read

### BLUF

NVD catalogued a root-impact command-injection CVE against Unitree Go2, G1, H1, and B2. IEEE Spectrum called it the first major public exploit of a commercial humanoid platform. This filing states **impact only**. No exploit steps, payloads, or reproduction procedures.

### Key judgments

1. **[Assessment — High confidence]** CVE-2025-35027 was published to NVD on **26 September 2025**. Affected products named: Unitree Go2, G1, H1, B2. CWE-78. CNA CVSS 3.1 **7.3 HIGH**.
2. **[Assessment — High confidence]** Impact as NVD states it: command injection via the Bluetooth Low Energy Wi-Fi configuration path; commands can run as root. No CPSC home-safety rule and no consumer-injury case attach to this CVE this month.
3. **[Inference — Moderate confidence]** A consumer-sold quadruped and a would-be home humanoid now share a national-vulnerability-catalog row. That is a Control Fabric fact, not a finding that home deployments were exploited.

### Analytic labels
- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades
- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution (typical for forums)

---

## 01. CVE-2025-35027 — Unitree Go2 / G1 / H1 / B2, NVD 26 September (impact only)

*Event / publication dates: researcher public disclosure ~20 September 2025; IEEE Spectrum 25 September 2025; NVD published 26 September 2025; Unitree LinkedIn statement 29 September 2025 (as quoted by Spectrum’s update)*

**Product class.** Emerging general-purpose or humanoid home robots; consumer / research quadrupeds (Go2, B2) and humanoids (G1, H1)

**Verified record — [Fact — A1 / B1]** NVD published **CVE-2025-35027** on **26 September 2025**. Description (impact): multiple Unitree products sharing common firmware — **Go2, G1, H1, and B2** — contain a command-injection vulnerability. Configuring onboard Wi-Fi via the BLE module can lead to commands running as root. CWE-78. CNA (Austin Hackers Anonymous) CVSS 3.1 **7.3 HIGH** (AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). NVD published date 26 September 2025. Source: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-35027).

*IEEE Spectrum*, **25 September 2025**, reported a critical vulnerability in the BLE Wi-Fi configuration interface affecting Go2, B2, G1, and H1, and wrote that as far as the magazine was aware this was “the first major public exploit of a commercial humanoid platform.” Spectrum’s 29 September update quoted a Unitree LinkedIn statement that the company had “completed the majority of the fixes” and that updates “will be rolled out… in the near future.” Source: [IEEE Spectrum](https://spectrum.ieee.org/unitree-robot-exploit).

**This filing states impact only. It does not describe exploit steps, payloads, handshake values, scripts, or reproduction procedures. It does not link readers to PoC repositories as a how-to.**

No CPSC, Health Canada, OPSS, or Safety Gate action on these models was found this month. No consumer-injury case was found. Go2 is sold into consumer and hobbyist channels; G1/H1/B2 sit in research, demo, and industrial-adjacent channels. All four are in the NVD row.

**Threat landscape.** Adjacent-radio command injection with root impact on a machine that Sense, Move, and Act. The trust object is who may command the body from BLE range. Physical harm is not documented on the NVD page.

**Forum / community notes.**
- none independently confirmed as Fact. Public PoC repositories exist and are **not** described here.

**Intelligence assessment.** [Assessment — High confidence] The CVE and the Spectrum date are established. [Inference — Moderate confidence] Shared firmware across quadruped and humanoid SKUs will keep producing class-wide rows. [Uncertainty] Whether a vendor fix actually shipped in September, and to which firmware ceilings, is not established from NVD (later NVD enrichment lists version ceilings; those enrichments post-date this month and are not treated as 30 September Facts).

**Opportunity.** A vendor advisory with patched versions, or a CISA ICS page, would move this from a catalog row to a consumer-assurance update. Watch for any claim that existing Go2s are “banned” — no such official action this month.

**LRRK relevance.** Control Fabric and Kestrel (who may command). Passport: firmware lineage, BLE provisioning exposure, signed update. Watch: NVD last-modified and any CISA follow-on. Lab: treat BLE provisioning as a first-class test, without republishing a method.

**Confidence.** High on NVD publication date, product names, CWE, and impact-to-root. Moderate on Spectrum’s “first commercial humanoid exploit” ranking. Low on September patch status.

---

## Forward indicators

Ranked watchlist as of 30 September 2025.

1. Unitree patched-version advisory that can be opened.
2. Any CISA or national ICS follow-on. Impact only if it arrives.
3. First priced consumer home-humanoid pre-order. Do not treat Figure as taking $20,000 deposits.
4. *Gomez* 1:25-cv-05622 motion practice.
5. Any official robot-vac or pool-robot recall (none this month).

> **Collection integrity.** Impact-only rule held: no exploit steps, payloads, or reproduction procedures. Related CVE IDs appearing on the same day in third-party write-ups were not opened as separate signals. No official product recall on Unitree was found. Forum and GitHub PoC material was seen and **refused** as a how-to source.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C3</span></p>