CVE Tools
Back to feed
PoC public Unitree G1 EDU mobile Unitree auth-bypass

Баги в роботах Unitree G1 EDU позволяют получить root-права

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Security researcher Olivier Laflamme has published details on two critical vulnerabilities, identified as CVE-2026-76639 and CVE-2026-76640, that affect Unitree G1 EDU humanoid robots running firmware versions 1.4.5 through 1.5.2. These flaws enable attackers to achieve full root access on the robot's Locomotion PC by leveraging path traversal and buffer overflow issues within specific software components. Notably, one attack vector initiates via Bluetooth Low Energy (BLE) without requiring prior pairing, and the researcher demonstrated that compromised units could potentially spread to other nearby robots in a worm-like fashion. While Unitree fixed a related cloud service issue in July 2026, it remains unclear whether public firmware updates containing fixes for the specific RCE vulnerabilities have been released.