Illustrative image generated with AI
FCC Bans Foreign Mobile Robots and Power Inverters: Third Supply Chain Ban Takes Effect
The FCC expanded its Covered List to ban new foreign mobile robots and connected power inverters due to national security risks and severe vulnerabilities.
Text generated by artificial intelligence, published without human review. AI transparency
On July 28, the Federal Communications Commission expanded its Covered List to include two new product categories: mobile robots and connected power inverters. From now on, no new imported models can obtain the certification required for sale in the United States. This marks the agency’s third categorical action, following bans on drones (December 2025) and home routers (March 2026). The move rests on two national security determinations transmitted on July 27, designating these devices as “foreign products” under the Buy American Act (48 CFR 25.101(a)) and setting the technical requirements for their listing. Already deployed devices and those in users’ possession remain usable, and federal procurement is unaffected.
What’s Being Targeted: Technical Definitions
The definition of mobile robot is deliberately broad. It includes humanoids, quadrupeds, and any mechanical device capable of terrestrial locomotion, weighing more than 4.4 pounds (including the base station), equipped with environmental sensors, wired or wireless connectivity of at least 200 kbps, and software for motion control and data collection – firmware and AI/ML model weights included. Connected road vehicles, drones, unmanned underwater vehicles, FDA-regulated medical devices, and fixed industrial arms (SCARA, Cartesian, Delta) are excluded.
For power inverters, the focus is on DC/AC or AC/DC conversion systems integrated with components capable of remote communication, control, sensing, or monitoring.
The Covered List does not name specific brands, but technical annexes cite documented vulnerabilities in Unitree robots (Go1, Go2, B2, G1, H1) and Sungrow, SMA, and Growatt inverters, plus an anonymous case of remote deactivation by a foreign manufacturer.
The Flaws That Triggered the Alarm
Research filed with the FCC paints a high-risk picture.
On mobile robots, researchers demonstrated the ability to intercept video and audio streams, reconstruct floor plans of monitored spaces, and gain root privileges. Several Bluetooth Low Energy CVEs (including CVE-2025-35027) and CVE-2025-2894 on the Unitree Go1, exploitable via the CloudSail service, even allow full remote control through APIs.
On the inverter front, Forescout’s SUN:DOWN investigation uncovered 46 vulnerabilities. In an adversarial scenario, these could trigger mass shutdowns, exfiltration of operational data, and grid manipulation with cascading effects. Texas grid operator ERCOT confirmed grid instability as the most serious threat. No active exploitation on already deployed devices has been identified: the measure is purely preventive.
Old Models Protected, New Ones on Hold
The ban does not freeze existing equipment. A waiver granted on July 28 explicitly authorizes the distribution of security and compatibility updates for previously certified devices, valid at least through January 1, 2029. Manufacturers intending to launch new models can apply for Conditional Approval by January 1, 2028.
The process involves a technical assessment: for robots, the authority is the Department of War (DoW); for inverters, the DoW or the Department of Homeland Security (DHS), depending on the deployment context.
Countermeasures for Organizations
Recommendations for entities already using these devices are specific:
- Promptly install security patches and software/firmware updates, now fully legitimate under the FCC waiver.
- Monitor outbound network traffic, especially toward unknown external destinations, to quickly detect anomalous communications.
- Manually check for official updates from the mentioned vendors (Unitree, Sungrow, SMA, Growatt, and others) and prioritize their application.
- For new models, initiate the Conditional Approval process with the technical documentation required by regulators.
No active emergency exists, but this is a systemic signal that reshapes American supply chain rules for robotics and energy.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2025-35027High7.3Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service,
- CVE-2025-2894Medium6.6The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail
