VMTech
Discuss a project

Unitree G1 EDU vulnerabilities enable root code execution

Unitree G1 EDU vulnerabilities enable root code execution

Security researcher Olivier Laflamme has disclosed two independent root remote-code-execution chains affecting Unitree’s G1 EDU humanoid robot. The issues, tracked as CVE-2026-76639 and CVE-2026-76640, can result in root-level execution on the robot’s Locomotion PC. One chain is network-adjacent; the other begins through Bluetooth Low Energy (BLE) proximity.

The research was published on August 27, 2026. Unitree had patched a cloud account-to-robot ownership check in July, which Laflamme said breaks the specific cloud-assisted proof of concept used in the BLE chain. However, accessible Unitree guidance does not confirm an exact firmware release that fixes either vulnerability.

Two separate paths to the Locomotion PC

CVE-2026-76639 involves a path-traversal condition in chat_go that can reach bashrunner. Code executed through bashrunner runs as root on the Locomotion PC. Laflamme described this as an independent RCE issue, even though he also used it as a disclosure primitive when demonstrating the separate BLE-based chain.

CVE-2026-76640 starts with an initial BLE write path that accepts the bootstrap interaction without Bluetooth pairing. The bootstrap material remains protected, and subsequent Wi-Fi provisioning actions require the application’s authenticated BLE state. The distinction matters because the initial unauthenticated contact alone does not expose the protected material or complete the chain.

Cloud authorization gap enabled the demonstrated BLE chain

During the research, Unitree’s cloud service accepted a valid Unitree account for a key-recovery request without verifying that the account owned the robot supplied in that request. That gap allowed recovery of key material associated with another G1 EDU. The recovered key could establish the authenticated BLE state needed to access Wi-Fi provisioning functions.

Laflamme documented a buffer overflow in the Wi-Fi provisioning code, which then produced root execution on the Locomotion PC. His propagation test was limited to two G1 robots in one room. As of the August 27 disclosure, the cloud-assisted route requires an account already bound to the target G1 or possession of the relevant key material.

Firmware status and product scope remain unclear

The research timeline records that the test robot was upgraded to version V1.5.2, but it does not independently establish that V1.5.1.1 is affected. Unitree’s product material treats the G1 and G1 EDU as separate models, and the applicability of these vulnerabilities to other Unitree robots remains unconfirmed.

For organisations operating G1 EDU systems, the immediate implication is to identify deployed robots, limit network and physical proximity where operationally possible, review access to associated Unitree accounts and key material, and obtain confirmed firmware and remediation guidance from Unitree before treating an update as a verified fix.

#iotsecurity#bluetooth#robotsecurity#vulnerability
Open analytics
On the site 0 views
min read 3 28.08.2026
Instagram

Unitree G1 EDU vulnerabilities enable root code execution

Open the post on Instagram ↗