Ethical Hacking News
Two critical vulnerabilities have been discovered in the Unitree G1 EDU humanoid robot, exposing remote code execution and Bluetooth vulnerabilities. The vulnerabilities, tracked as CVE-2026-76639 and CVE-2026-76640, have significant implications for the security of the robot and the broader IoT ecosystem. As a result, users and manufacturers are urged to take proactive steps to address these vulnerabilities and ensure the security of their devices.
Two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU humanoid robot have been disclosed. The vulnerabilities, CVE-2026-76639 and CVE-2026-76640, have significant implications for the security of the robot and the broader IoT ecosystem. A patch has been released to mitigate the risks, but an exact fixed firmware release has not been verified. The vulnerabilities can be exploited through a network-adjacent vulnerability or a Bluetooth Low Energy (BLE) proximity attack. The implications of these vulnerabilities are far-reaching, with potential risks to other Unitree robots unconfirmed. Manufacturers and users must remain vigilant and proactive in identifying and addressing vulnerabilities before they can be exploited.
The cybersecurity landscape continues to evolve with each new day, presenting numerous challenges and vulnerabilities for manufacturers and users alike. In recent news, a security researcher named Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU humanoid robot. These vulnerabilities, tracked as CVE-2026-76639 and CVE-2026-76640, have significant implications for the security of the robot and, by extension, the broader IoT ecosystem.
Laflamme's research highlights two distinct RCE paths that can be exploited to gain root-level access on the Locomotion PC of the robot. The first path, CVE-2026-76639, exploits a network-adjacent vulnerability in the chat_go and bashrunner software, while the second path, CVE-2026-76640, leverages a Bluetooth Low Energy (BLE) proximity attack to achieve the same goal. This BLE vulnerability allows an attacker to access the robot's Locomotion PC without requiring a paired connection.
In a bid to mitigate the risks associated with these vulnerabilities, Unitree patched the cloud account-to-robot ownership check in July 2026. However, as of the time of the disclosure, an exact fixed firmware release has not been verified in any accessible Unitree guidance. This leaves G1 EDU owners without a confirmed release target for either vulnerability, thereby increasing the risk of potential exploitation.
Laflamme's research timeline shows that the robot was upgraded to V1.5.2, but this upgrade sequence does not establish V1.5.1.1 as affected. This indicates that further research is required to understand the full scope of the vulnerabilities and to develop effective patches.
The technical disclosure provided by Laflamme offers a detailed explanation of the vulnerabilities and their respective attack vectors. For CVE-2026-76639, the vulnerability is described as a path-traversal condition in chat_go, which allows the attacker to reach bashrunner and subsequently execute root code on the Locomotion PC. This vulnerability is considered independent, although Laflamme reused it as a disclosure primitive while demonstrating the separate BLE chain tracked as CVE-2026-76640.
The second vulnerability, CVE-2026-76640, leverages an initial BLE write path that accepts a bootstrap interaction without Bluetooth pairing. The bootstrap material itself remains protected, and the later Wi-Fi provisioning operations require the application's authenticated BLE state. During Laflamme's research, Unitree's cloud service accepted a valid Unitree account for the key-recovery request but did not verify that the account owned the supplied robot. This authorization gap allowed the account to recover key material associated with another G1 EDU, which could then be used to establish the authenticated BLE state required by the Wi-Fi provisioning operations.
The chain of events then reaches the Wi-Fi provisioning code, where a documented buffer overflow results in root execution on the Locomotion PC. Laflamme documented this attack path, but noted that the cloud authorization fix breaks the exact proof-of-concept flow. This means that while the vulnerability has been patched, it is still possible for an attacker to exploit the vulnerability using alternative attack vectors.
The implications of these vulnerabilities are far-reaching, with Unitree distinguishing the G1 and G1 EDU as separate models in their official product page. However, the broader applicability of these vulnerabilities to other Unitree robots remains unconfirmed, leaving users and manufacturers uncertain about the potential risks.
In light of these disclosures, it is essential to emphasize the importance of vigilance and proactive security measures for all IoT devices, including humanoid robots like the Unitree G1 EDU. As the threat landscape continues to evolve, manufacturers and users must remain vigilant and proactive in identifying and addressing vulnerabilities before they can be exploited.
Related Information:
https://www.ethicalhackingnews.com/articles/Two-Critical-Vulnerabilities-in-Unitree-G1-EDU-Humanoid-Robot-Expose-Remote-Code-Execution-and-Bluetooth-Vulnerabilities-ehn.shtml
https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html
Published: Sat Aug 29 17:57:53 2026 by llama3.2 3B Q4_K_M