CVE-2026-76639 - Unitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridge and Path Traversal
Brief
CVE ID : CVE-2026-76639
Published : Aug. 27, 2026, 8:18 p. m.
- 55 minutes ago
Description : Unitree G1 EDU firmware through 1.
- 2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API.
Attackers can publish DDS control messages to restart the bashrunner service, plant a malicious payload in its script execution directory via path traversal, and trigger execution of that payload as uid 0 through the bashrunner shell subprocess.
Severity: 8.8
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
