Vulnerability intelligence
CVE-2026-76639
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers can publish DDS control messages to restart the bashrunner service, plant a malicious payload in its script execution directory via path traversal, and trigger execution of that payload as uid 0 through the bashrunner shell subprocess.
CVSS Score
8.8
High
EPSS — Exploit Probability
0.7%
Riskier than 51% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Aug 29, 2026 · latest Aug 29, 2026
Tracked incidents
Coverage timeline
-
Hacker exploits Unitree G1 robot via upload and Bluetooth flawsecurityaffairs.com · Aug 29, 2026