CVE Tools
Back to feed
Research Unitree G1 EDU ics-ot-iot Unitree rce

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Security researcher Olivier Laflamme has revealed two distinct remote code execution vulnerabilities, CVE-2026-76639 and CVE-2026-76640, affecting the Unitree G1 EDU humanoid robot. These flaws enable attackers to achieve root-level control over the device's Locomotion PC through a network-adjacent path-traversal issue and a Bluetooth Low Energy-based buffer overflow, respectively. While Unitree addressed a related cloud authorization weakness in July 2026, no specific firmware patch for these newly identified exploits has been officially verified.