Unitree G1 EDU Flaws Reach Root Over BLE

Olivier Laflamme published two root remote code execution chains against the Unitree G1 EDU on August 27, including CVE-2026-76640, which starts from Bluetooth Low Energy (BLE) proximity and reaches the robot’s locomotion PC. He also described CVE-2026-76639, a separate chain that goes through chat_go and bashrunner. The BLE path accepts an initial setup write from someone nearby without pairing, then uses cloud key-recovery and authenticated provisioning to move into Wi‑Fi setup code, where a buffer overflow lands root on the locomotion PC. Unitree has fixed the cloud account-to-robot ownership check, but the reported firmware status is still unsettled because no publicly verified fixed release is available. For owners of the G1 EDU, the exposure is not just in cloud binding: a person close to the robot may still be able to reach the control plane through BLE and end at root on the machine that drives movement. Until a verified firmware target exists, the remaining risk sits with physical access and provisioning workflows, not only with accounts.

Part of the PlainSec briefing for 2026-08-28

Editions

Sources