US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities (CVE-2025-35027) — Threadlinqs Intelligence
As of 2026-07-29, US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities (CVE-2025-35027) is a high-severity supply chain threat attributed to a China-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1751 · Severity: HIGH · CVSS: 7.3 · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: China · ESPIONAGE
On 2026-07-28 the FCC, acting on a White House National Security Determination, added foreign-made advanced robotic devices (humanoid and quadruped robots) and connected power inverters to its Covered
On July 27-28, 2026, an Executive Branch interagency national-security body sent the FCC a National Security Determination covering foreign-produced advanced robotic devices and connected power inverters, and the FCC (under Chairman Brendan Carr) formally added both categories to its Covered List under the Secure and Trusted Communications Networks Act framework, barring new models from receiving the equipment authorization required to import, market, or sell wireless devices in the United States. The determination is prospective (already-authorized models may continue to be sold) and can be overridden with case-by-case approval from the Departments of War or Homeland Security; federal agencies retain purchasing authority.
The order's cybersecurity rationale rests heavily on a documented pattern of critical vulnerabilities in Unitree's robot line, the dominant Chinese humanoid/quadruped vendor (with Agibot and UBTech). Most prominently, the 'UniPwn' vulnerability chain (publicly disclosed 2025-09-20, tracked as CVE-2025-35027 plus CVE-2025-60017, CVE-2025-60250 and CVE-2025-60251) combines a hardcoded AES-CFB128 key/IV, a trivial string-match authentication bypass, and unsanitized command injection in the robot's Bluetooth Low Energy WiFi-configuration interface. An attacker in BLE range sends an AES-encrypted 'unitree' string to bypass authentication, then injects a shell command into the SSID/password fields (';$(cmd);#'), which executes as root via wpa_supplicant_restart.sh when the WiFi service restarts. The exploit is wormable: a compromised robot can scan for and infect nearby Unitree units over BLE without operator interaction, enabling a robot botnet. The flaw was privately reported to Unitree from April 2025 onward; the manufacturer was unresponsive and reportedly said a fix would take 'quarters or years,' prompting public disclosure five months later with no confirmed comprehensive patch.
A second, independently disclosed RCE chain affects the Unitree Go2 specifically (CVE-2026-27509, CVE-2026-27510; publicly documented 2026-02-27, patched in firmware V1.1.13). The Go2 runs Eclipse CycloneDDS for inter-process control messaging over an unauthenticated publish/subscribe bus; an attacker who joins DDS Domain 0 can publish a crafted 'Request_' message with api_id=1002 to the 'rt/api/programming_actuator/request' topic, causing the robot to write attacker-supplied Python to disk at /unitree/etc/programming/{uuid}.py and bind it to a physical controller hotkey — full root RCE requiring only a single button press to trigger, with no authentication or payload validation anywhere in the chain (CVE-2026-27509). When Unitree hardened DDS topic discovery, a companion vector (CVE-2026-27510) achieved the same outcome via tampering with the Android companion app's local SQLite database (dog_programme table) and re-syncing it to the robot.
These acute flaws sit atop an older, still-unpatched supply-chain issue: the discontinued Go1 quadruped (CVE-2025-2894, disclosed by Austin Hackers Anonymous on 2025-03-27) ships with an undocumented backdoor — the CloudSail remote-access service operated by Chinese firm Zhexi Technology — that auto-starts on boot and opens a persistent peer-to-peer tunnel giving anyone with the correct API key full remote control, camera access, and network pivot capability, without owner knowledge or a patch. Vulnerable Go1 units were confirmed operating inside networks at MIT, Princeton, Carnegie Mellon, and the University of Waterloo, and Go2/G1/H1 units are deployed in sensitive contexts including UK police armed-response units and China's PLA. This recurring pattern of embedded/default-credential backdoors, unresponsive vendor disclosure handling, and unauthenticated network/BLE control surfaces is the direct evidentiary basis for the FCC's 'broad attack surfaces' and OTA-update-risk language in the National Security Determination. The same July 2026 action separately targets Chinese-made grid-connected
Target sectors: government administration, police - law enforcement, defense, academia, energy, manufacturing, robotics
Target regions: North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, CVE-2025-35027, CVE-2025-60017, CVE-2025-60250, CVE-2025-60251, CVE-2025-2894, CVE-2026-27509, CVE-2026-27510, T1595, T1592, T1588, T1587, T1195, T1078, T1059, T1203, T1546, T1068