< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

Unitree G1 EDU robots face critical root access vulnerabilities

Security researcher Olivier Laflamme has identified two critical vulnerabilities in the Unitree G1 EDU humanoid robot that could allow attackers to gain full root-level control. The flaws, documented as CVE-2026-76639 and CVE-2026-76640, involve distinct attack vectors.

The first vulnerability, dubbed ‘UniBLEed’, exploits Bluetooth Low Energy (BLE). It allows an unauthenticated attacker within radio range to bypass pairing requirements and access the robot’s system. This attack chain is described as potentially wormable, meaning a compromised robot could autonomously attack other G1 units in proximity.

The second vulnerability involves flaws in Unitree’s cloud authorization process. An attacker can use a standard Unitree account to request the decryption of a robot’s unique AES-128 encryption key via the cloud API, as the system fails to verify if the account holder actually owns the targeted device. This allows for the recovery of device-specific keys used for secure communication.

Additionally, a separate attack chain was identified involving the robot’s AI chatbot service. By exploiting a path traversal vulnerability, an attacker could write arbitrary files to the filesystem and execute code with root privileges via the ‘bashrunner’ service.

Entities

Olivier Laflamme · Unitree · Unitree G1 EDU

Claims

What the coverage asserts, and how many sources carry each claim.