Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
ResearchUnitree G1 EDUOur summary
Security researcher Olivier Laflamme has revealed two distinct remote code execution vulnerabilities, CVE-2026-76639 and CVE-2026-76640, affecting the Unitree G1 EDU humanoid robot. These flaws enable attackers to achieve root-level control over the device's Locomotion PC through a network-adjacent path-traversal issue and a Bluetooth Low Energy-based buffer overflow, respectively. While Unitree addressed a related cloud authorization weakness in July 2026, no specific firmware patch for these newly identified exploits has been officially verified.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.