Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Hack One Robot, Reach the Next: Unitree G1 Security Flaws

A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby. Security researcher Olivier Laflamme spent about three months digging into the Unitree G1 humanoid robot and eventually found a way to fully compromise it without plugging in a single cable. In his technical write-up , he details two vulnerabilities, CVE-2026-76639 and CVE-2026-76640, that can be chained across Bluetooth, Unitree’s cloud infrastructure, the mobile app, and the robot’s firmware to gain unauthenticated root access to any G1 within Bluetooth range. The first bug lives entirely inside the robot itself, no wireless attack surface needed if you can reach it over Ethernet.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

Hackers Can Take Full Control of Unitree G1 Humanoid Robots Over Bluetooth

A critical attack chain could let attackers within Bluetooth range take full control of Unitree G1 humanoid robots , gaining root-level code execution on the locomotion computer that controls movement, cameras, speakers, voice features, and other peripherals. The flaws could allow a nearby attacker to obtain root-level code execution on the robot’s locomotion computer, which manages major hardware functions, including movement, cameras, speakers, voice features, and other peripherals. The research, dubbed UniBLEed, describes a multi-stage exploit involving Bluetooth Low Energy , Unitree’s cloud API, Wi-Fi provisioning system, and services running on the robot’s Linux-based control environment. Hackers Control Unitree G1 Robots The attack was assigned CVE-2026-76639 and CVE-2026-76640 and was reportedly reproduced on four Unitree G1 robots.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-76639 - Unitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridge and Path Traversal

CVE ID : CVE-2026-76639 Published : Aug. 27, 2026, 8:18 p. m. • 55 minutes ago Description : Unitree G1 EDU firmware through 1. 5. 2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers can publish DDS control messages to restart the bashrunner service, plant a malicious payload in its script execution directory via path traversal, and trigger execution of that payload as uid 0 through the bashrunner shell subprocess. Severity: 8.8 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

·CVEFeed
Read →

You've reached the end of current stories for this search.