CVE-2026-76639
Unitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridge and Path Traversal
Description
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers can publish DDS control messages to restart the bashrunner service, plant a malicious payload in its script execution directory via path traversal, and trigger execution of that payload as uid 0 through the bashrunner shell subprocess.
CVSS Vector Breakdown
AV:AAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
4 techniquesReferences
- Баги в роботах Unitree G1 EDU позволяют получить root-праваru-ru·Хакер (xakep.ru)· PoC Unitree G1 EDU mobile
- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and Moreen·The Hacker News· Exploited ZBT Routers QTYF
- Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetoothen·The Hacker News· Research Unitree G1 EDU ics-ot-iot
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-76639 and every CVE in our database. Create a free account — no credit card required.
Create Free Account