Researchers have uncovered two critical remote code execution flaws in Unitree’s G1 EDU humanoid robot, exposing potential for unauthorised root access via network and Bluetooth vectors amidst ongoing firmware concerns.
Security researcher Olivier Laflamme has disclosed two separate root remote code execution flaws in Unitree’s G1 EDU humanoid robot, according to reporting by The Hacker News. The issues are tracked as CVE-2026-76639 and CVE-2026-76640, and they affect different parts of the robot’s software stack. One route relies on network-adjacent access, while the other can be triggered through Bluetooth Low Energy proximity without prior pairing.
The first flaw, CVE-2026-76639, is described as an unauthenticated attack chain that can end in root-level code execution on the robot’s Locomotion PC. Reports from The Hacker Wire, Tenable and SeCalerts say the chain combines an exposed WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key with world-readable permissions, and a path traversal weakness in the chat_go knowledge upload interface. In practice, this could let an attacker publish control messages, restart the bashrunner service, place a malicious payload and execute it as UID 0.
The second issue, CVE-2026-76640, takes a different route through the robot’s Bluetooth and Wi-Fi provisioning components. According to The Hacker News and CVE trackers, a nearby attacker can begin a bootstrap exchange without pairing, then abuse a buffer overflow during provisioning to gain root execution. CVEFeed says the weakness can corrupt a dispatch entry in the main loop and ultimately pass attacker-controlled input to system() with root privileges.
A separate authorisation flaw in Unitree’s cloud service, which had allowed key material recovery for unauthorised accounts, has reportedly been fixed. Even so, as of the August 27 disclosure, no publicly verified firmware update for the G1 EDU had been confirmed, leaving owners without a clear remediation target. The wider question of whether the same flaws affect other Unitree models remains unresolved.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





