← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 27, 2026 · 20:18via CVEFeed

CVE-2026-76639 - Unitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridge and Path Traversal

Brief

CVE ID : CVE-2026-76639

Published : Aug. 27, 2026, 8:18 p. m.

  • 55 minutes ago

Description : Unitree G1 EDU firmware through 1.

  • 2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API.

Attackers can publish DDS control messages to restart the bashrunner service, plant a malicious payload in its script execution directory via path traversal, and trigger execution of that payload as uid 0 through the bashrunner shell subprocess.

Severity: 8.8

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed