StoryOther
Two more root-level security flaws reported in the Unitree G1 EDU, one reachable over Bluetooth
Researcher Olivier Laflamme disclosed two independent root remote-code-execution flaws in the Unitree G1 EDU. One exploits a network path-traversal bug through the chat_go service; the other—accessible over Bluetooth without pairing—exploits a buffer overflow in the Wi-Fi setup service. Both grant full root control. Unitree patched a related cloud check in July 2026, but no fixed firmware had been confirmed available.
- CVE-2026-76639 (network) and CVE-2026-76640 (Bluetooth) enable unauthenticated root RCE.
- Bluetooth path: unquoted heredoc variable in WiFi provisioning script + buffer overflow in SSID accumulator.
- Network path: path-traversal through chat_go service and bashrunner; Bluetooth accessible without pairing or credentials.
- Both flaws grant full root control of robot including movement, sensors, cloud credentials; Unitree patched related issue in July but no fixed firmware confirmed for either CVE.