logo

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

ID: 24d8a577-d18a-53c5-91d9-869ca8c187be

STIX ID: report--24d8a577-d18a-53c5-91d9-869ca8c187be

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

Author: [email protected] (The Hacker News)

...
...

Olivier Laflamme disclosed two independent root remote code execution chains (CVE-2026-76639 and CVE-2026-76640) impacting the Unitree G1 EDU robot: one path exploits a chat_go path-traversal to reach bashrunner and obtain root on the Locomotion PC, while the other starts from an unauthenticated BLE bootstrap, leverages a cloud account-to-robot ownership gap to recover keys, and triggers a Wi‑Fi provisioning buffer overflow for root. Unitree reportedly patched the cloud ownership check, but the exact fixed firmware versions and wider product applicability remain unverified; Laflamme's proof-of-concept was limited and no in-the-wild exploitation is reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.