DEV Community

Mark0
Mark0

Posted on

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

Security researcher Olivier Laflamme has disclosed two critical root remote code execution (RCE) chains affecting the Unitree G1 EDU humanoid robot. Tracked as CVE-2026-76639 and CVE-2026-76640, these vulnerabilities allow an attacker to gain full control over the robot's Locomotion PC through network-adjacent path traversal or Bluetooth Low Energy (BLE) proximity exploitation.

While Unitree has addressed a cloud-side authorization gap that previously allowed unauthorized retrieval of robot key material, the underlying firmware vulnerabilities involving buffer overflows and path traversal remain a concern. As of the disclosure, a verified firmware fix for the G1 EDU hardware has not been confirmed, leaving owners to rely on the manufacturer's cloud-level remediations to mitigate the specific proof-of-concept attack chains.


Read Full Article

Top comments (0)