Security Research Reveals Critical Unitree G1 EDU Root RCE Vulnerabilities

Published:

Security researcher Olivier Laflamme has disclosed two independent root remote code execution vulnerabilities affecting the Unitree G1 EDU humanoid robot, including one attack chain that begins through Bluetooth Low Energy (BLE) communication. The vulnerabilities, tracked as CVE 2026 76639 and CVE 2026 76640, could allow attackers to gain root level code execution on the robot’s Locomotion PC through different attack paths. According to the research published on August 27, 2026, the two vulnerabilities are separate exploitation chains, with one relying on a network adjacent attack while the other begins with Bluetooth proximity. At the time of disclosure, no official guidance from Unitree confirmed a firmware version that fully addresses either vulnerability, leaving G1 EDU owners without a verified update target.

According to Laflamme’s technical analysis, CVE 2026 76639 exploits a path traversal condition in the chat_go component to reach bashrunner, ultimately allowing attackers to execute code with root privileges on the Locomotion PC. Although this vulnerability represents a complete remote code execution chain on its own, the researcher also used it as part of demonstrating the second vulnerability, CVE 2026 76640. The Bluetooth based attack starts with a BLE write operation that accepts the initial bootstrap interaction without requiring Bluetooth pairing. While the bootstrap information itself remains protected, subsequent Wi Fi provisioning functions require an authenticated BLE session. During the research, Laflamme found that Unitree’s cloud service accepted a valid Unitree account when processing key recovery requests but did not verify whether the requesting account actually owned the robot specified in the request. This authorization weakness allowed recovery of key material associated with another G1 EDU, enabling the authenticated BLE state required for later stages of the attack. After reaching the Wi Fi provisioning process, the researcher identified a buffer overflow vulnerability that resulted in root level code execution on the robot.

Laflamme noted that Unitree addressed the cloud authorization issue in July 2026 by updating the account to robot ownership verification process. Following that change, the previously demonstrated cloud assisted attack path now requires either an account already linked to the target robot or possession of the appropriate cryptographic key material. The researcher also stated that the proof of concept propagation test was limited to two G1 robots located in the same room and confirmed that the July cloud authorization update prevents that specific attack sequence from succeeding. While the research timeline indicates that testing was performed after upgrading the evaluation device to firmware version V1.5.2, the published information does not confirm whether firmware version V1.5.1.1 or earlier releases are affected. As of the disclosure date, Unitree had not publicly identified the firmware versions that resolve the vulnerabilities or clarified the full scope of affected devices.

The research currently applies specifically to the Unitree G1 EDU model, while broader applicability to other Unitree robots remains unconfirmed. Unitree’s official product documentation distinguishes the standard G1 model from the G1 EDU edition, and no confirmation has been provided regarding whether similar vulnerabilities exist in other products. The Hacker News reported that it had contacted Unitree for clarification regarding affected firmware versions, remediation status, and the range of impacted products, with no public response available at the time of publication. The disclosure highlights the growing importance of cybersecurity within robotics platforms as connected systems increasingly integrate wireless communications, cloud services, and remote management capabilities, making timely security updates and vulnerability remediation essential for organizations deploying advanced robotic technologies.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img