<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth]]></title><description><![CDATA[<p dir="auto">Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the <em>Unitree G1 EDU</em> humanoid robot, with one attack vector requiring only Bluetooth proximity to fully compromise the system.</p>
<p dir="auto">The first flaw, tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76639" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-76639</a></strong>, involves a network-adjacent exploitation path that chains through the <code>chat_go</code> service and <code>bashrunner</code> component. This route allows an attacker on the same network to escalate privileges to root on the robot's Locomotion PC without authentication.</p>
<p dir="auto">The second vulnerability, <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76640" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-76640</a></strong>, is notably more severe in terms of attack scope. It enables a remote attacker to trigger the same root-level compromise over <strong>Bluetooth Low Energy (BLE)</strong>, meaning an adversary within wireless range of the robot can achieve full system control without any prior network access.</p>
<ul>
<li>Affected product: Unitree G1 EDU humanoid robot</li>
<li>Impact: Root-level remote code execution</li>
<li>Attack vectors: Network-adjacent (via <code>chat_go</code>/<code>bashrunner</code>) and BLE proximity</li>
</ul>
<p dir="auto">Both chains ultimately lead to complete control of the Locomotion PC, which handles critical locomotion and navigation functions. Laflamme's disclosure highlights the growing attack surface in consumer-grade robotics, where embedded systems often prioritize functionality over security hardening.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Are you or your team deploying Unitree robots, and if so, how are you isolating the BLE and network interfaces from untrusted environments?</p>
]]></description><link>https://xploitlk.com/topic/143/two-unitree-g1-edu-humanoid-robot-flaws-enable-root-rce-one-starts-over-bluetooth</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:30:40 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/143.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 29 Aug 2026 14:30:26 GMT</pubDate><ttl>60</ttl></channel></rss>