Unitree Go2 unauthenticated DDS DataWriter root shell, CVE-2026-27509/27510
Injury / Loss of control
Public PoC
Trusted
Business relevance
boschko.ca · 2026-09-05
ref CVE-2026-27509 (V1.1.7) · CVE-2026-27510 (V1.1.11) · Same-network DDS probes/Android local database · Nearby WiFi/Ethernet access · Under $100
Link hijack → stack control → execution: abuse of
rt/api/programming_actuator/* DDS executes arbitrary Python as root. CVE-27510 achieves the same through local Android Blockly action blocks. Surface spans the Unitree ecosystem.
Reproduction notes : Expected effects: full takeover, arbitrary motion/surveillance. Isolated sites/used hardware only; never crowds, exhibitions or customer demonstrations.
