LC-3 · Consumer Risk Bulletins
Kinematic Risk Consumer Bulletin
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# Kinematic Risk Consumer Bulletin **LRRK Watch / Open-Source Intelligence** — Consumer kinematic electronics. Monthly filing. **Issue type.** Monthly KRCB (retrospective). LC-3 (Consumer). Not the weekday 24–48h poll. | Field | Value | | --- | --- | | Collection cutoff | 30 September 2025 | | Window | 1–30 September 2025 | | Written | 19 August 2026 (retrospective reconstruction) | | Data label | Open-source intelligence // LRRK analytic product // retrospective monthly filing | | Handling | Public-source material. Image rights require separate verification before publication. | | Scope | Consumer kinematic electronics only (home, yard, companion, educational). | | Classes in frame | Robot vacuums / mop combos · robotic lawn mowers · window-cleaning robots · pool-cleaning robots · robot pets / companion animals · social / desk companions · educational / programmable kits · robotic litter boxes · security / home patrol robots · consumer robotic arms · elder-care / assistive companions · kitchen / food-prep robots · toy / entertainment robots · niche outdoor / garden robots · emerging general-purpose or humanoid home robots | | Spine | Reputable channels for injury, death, incidents, and safety recalls (CPSC, Health Canada, EU Safety Gate, UK OPSS, manufacturer recall pages, named newsrooms, dockets). | | Color | Message boards, consumer forums, and Reddit — annotated context only. Never Fact without a reputable primary. | ## Executive read ### BLUF NVD catalogued a root-impact command-injection CVE against Unitree Go2, G1, H1, and B2. IEEE Spectrum called it the first major public exploit of a commercial humanoid platform. This filing states **impact only**. No exploit steps, payloads, or reproduction procedures. ### Key judgments 1. **[Assessment — High confidence]** CVE-2025-35027 was published to NVD on **26 September 2025**. Affected products named: Unitree Go2, G1, H1, B2. CWE-78. CNA CVSS 3.1 **7.3 HIGH**. 2. **[Assessment — High confidence]** Impact as NVD states it: command injection via the Bluetooth Low Energy Wi-Fi configuration path; commands can run as root. No CPSC home-safety rule and no consumer-injury case attach to this CVE this month. 3. **[Inference — Moderate confidence]** A consumer-sold quadruped and a would-be home humanoid now share a national-vulnerability-catalog row. That is a Control Fabric fact, not a finding that home deployments were exploited. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution (typical for forums) --- ## 01. CVE-2025-35027 — Unitree Go2 / G1 / H1 / B2, NVD 26 September (impact only) *Event / publication dates: researcher public disclosure ~20 September 2025; IEEE Spectrum 25 September 2025; NVD published 26 September 2025; Unitree LinkedIn statement 29 September 2025 (as quoted by Spectrum’s update)* **Product class.** Emerging general-purpose or humanoid home robots; consumer / research quadrupeds (Go2, B2) and humanoids (G1, H1) **Verified record — [Fact — A1 / B1]** NVD published **CVE-2025-35027** on **26 September 2025**. Description (impact): multiple Unitree products sharing common firmware — **Go2, G1, H1, and B2** — contain a command-injection vulnerability. Configuring onboard Wi-Fi via the BLE module can lead to commands running as root. CWE-78. CNA (Austin Hackers Anonymous) CVSS 3.1 **7.3 HIGH** (AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). NVD published date 26 September 2025. Source: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-35027). *IEEE Spectrum*, **25 September 2025**, reported a critical vulnerability in the BLE Wi-Fi configuration interface affecting Go2, B2, G1, and H1, and wrote that as far as the magazine was aware this was “the first major public exploit of a commercial humanoid platform.” Spectrum’s 29 September update quoted a Unitree LinkedIn statement that the company had “completed the majority of the fixes” and that updates “will be rolled out… in the near future.” Source: [IEEE Spectrum](https://spectrum.ieee.org/unitree-robot-exploit). **This filing states impact only. It does not describe exploit steps, payloads, handshake values, scripts, or reproduction procedures. It does not link readers to PoC repositories as a how-to.** No CPSC, Health Canada, OPSS, or Safety Gate action on these models was found this month. No consumer-injury case was found. Go2 is sold into consumer and hobbyist channels; G1/H1/B2 sit in research, demo, and industrial-adjacent channels. All four are in the NVD row. **Threat landscape.** Adjacent-radio command injection with root impact on a machine that Sense, Move, and Act. The trust object is who may command the body from BLE range. Physical harm is not documented on the NVD page. **Forum / community notes.** - none independently confirmed as Fact. Public PoC repositories exist and are **not** described here. **Intelligence assessment.** [Assessment — High confidence] The CVE and the Spectrum date are established. [Inference — Moderate confidence] Shared firmware across quadruped and humanoid SKUs will keep producing class-wide rows. [Uncertainty] Whether a vendor fix actually shipped in September, and to which firmware ceilings, is not established from NVD (later NVD enrichment lists version ceilings; those enrichments post-date this month and are not treated as 30 September Facts). **Opportunity.** A vendor advisory with patched versions, or a CISA ICS page, would move this from a catalog row to a consumer-assurance update. Watch for any claim that existing Go2s are “banned” — no such official action this month. **LRRK relevance.** Control Fabric and Kestrel (who may command). Passport: firmware lineage, BLE provisioning exposure, signed update. Watch: NVD last-modified and any CISA follow-on. Lab: treat BLE provisioning as a first-class test, without republishing a method. **Confidence.** High on NVD publication date, product names, CWE, and impact-to-root. Moderate on Spectrum’s “first commercial humanoid exploit” ranking. Low on September patch status. --- ## Forward indicators Ranked watchlist as of 30 September 2025. 1. Unitree patched-version advisory that can be opened. 2. Any CISA or national ICS follow-on. Impact only if it arrives. 3. First priced consumer home-humanoid pre-order. Do not treat Figure as taking $20,000 deposits. 4. *Gomez* 1:25-cv-05622 motion practice. 5. Any official robot-vac or pool-robot recall (none this month). > **Collection integrity.** Impact-only rule held: no exploit steps, payloads, or reproduction procedures. Related CVE IDs appearing on the same day in third-party write-ups were not opened as separate signals. No official product recall on Unitree was found. Forum and GitHub PoC material was seen and **refused** as a how-to source. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C3</span></p>